3 ms·
So what alternatives are there to protecting HTTP? Is something like CurveCP feasible?
by DASD 13y ago
So what alternatives are there to protecting HTTP? Is something like CurveCP feasible?
- graue 13y agoTACK (http://tack.io/ http://tack.io/), if widely implemented, would help a lot. As I understand it, if you visited a website regularly before it was compromised, then any future compromise along the lines described in the article (i.e., without stealing the server's private key) wouldn't affect you. I'm not sure if TACK is still alive or how on-board with it any browser developers are.
- itistoday2 13y agoSome concerns about CurveCP's performance. Development seems slow from what I've been able to glean from the site and list: http://comments.gmane.org/gmane.network.curvecp/65 http://comments.gmane.org/gmane.network.curvecp/65 http://i.imgur.com/VMDdTQ3.png http://i.imgur.com/VMDdTQ3.png
- itistoday2 13y agoThe EFF's answer to this seems to be: HTTPS Everywhere + SSL Observatory + Sovereign Keys: https://www.eff.org/encrypt-the-web https://www.eff.org/encrypt-the-web