5 ms·
They clearly mention this goal in their blog post: http://blog.wikimedia.org/2013/08/01/future-https-wikimedia-projects/ http://blog.wikimedia.org/2013/08/01/f
by semenko 13y ago
They clearly mention this goal in their blog post:
http://blog.wikimedia.org/2013/08/01/future-https-wikimedia-projects/ http://blog.wikimedia.org/2013/08/01/future-https-wikimedia-...
- kudu 13y agoWikimedia seems to make a habit out of "considering" things for a long time before actually enabling them. Enabling forward secrecy is relatively straightforward.
- Skalman 13y agoYes. However, if you do that, perhaps you're less motivated to find solutions to other, equally important problems with HTTPS. Enabling perfect forward secrecy is only useful if we also eliminate the threat of traffic analysis of HTTPS, which can be used to detect a user’s browsing activity, even when using HTTPS.
- mpyne 13y agoTraffic analysis is certainly an orthogonal problem to decryption of the ciphertext here. There's no reason to wait on one for the other.
- Sujan 13y agoAt the scale of Wikimedia nothing is straightforward. Not even relatively.
- davidgerard 13y agoThis. We're talking about the fifth most popular site on the Web, operating on a budget smaller than my department at work.