4 ms·
First 80% of the article was great, but it ends a bit handwavey when it gets to its conclusion. One thing the article gets wrong is that non-encrypted HTTP/2 e
by treve 2y ago
First 80% of the article was great, but it ends a bit handwavey when it gets to its conclusion.
One thing the article gets wrong is that non-encrypted HTTP/2 exists. Not between browsers, but great between a load balancer and your application.
- fragmede 2y agoNot according to Edward Snowden, if you're Yahoo and Google.
- ChocolateGod 2y agoYou can just add encryption to your backend private network (e.g. Wireguard) Which has the benefit of encrypting everything and avoids the overhead of starting a TLS socket for every http connection.
- jeroenhd 2y agoIf you're going that route, you may as well just do HTTPS again. If you configure your TLS cookies and session resumption right, you'll get all of the advantages of fancy post-quantum crypto without having to go back to the days of manually setting up encrypted tunnels like when IPSec did the rounds.
- soraminazuki 2y agoWait, are some people actively downvoting advice encouraging the use of encryption in internal networks? I sure hope those people don't go anywhere near the software industry because that's utterly reckless in the post-Snowden world.
- fragmede 2y agoPeople are all over the place. I had to talk someone into SSH over VPN being double encrypted isn’t a waste.
- tuukkah 2y agoDo you want to risk the complexity and potential performance impact from the handshake that the HTTP/2 standard requires for non-encrypted connections? Worst case, your client and server toolings clash in a way that every request becomes two requests (before the actual h2c request, a second one for the required HTTP/1.1 upgrade, which the server closes as suggested in the HTTP/2 FAQ).
- arccy 2y agomost places where you'd use it use h2c prior knowledge, that is, you just configure both ends to only speak h2c, no upgrades or downgrades.
- byroot 2y ago> One thing the article gets wrong is that non-encrypted HTTP/2 exists Indeed, I misread the spec, and added a small clarification to the article.