4 ms·
It's disappointing to hear that the idea of requiring TLS with HTTP/2 has lost traction. For me, TLS-everywhere was the carrot on the stick. I recognize that g
by rx4g 12y ago
It's disappointing to hear that the idea of requiring TLS with HTTP/2 has lost traction. For me, TLS-everywhere was the carrot on the stick.
I recognize that getting consensus is hard work, but I don't think creating another encryption-optional protocol and letting vendors duke it over security is going to end well for the users.
HTTP is a deployed protocol with lots of existing
stakeholders, like proxy vendors, network operators,
corporate firewalls and so on. Requiring encryption
with HTTP/2 means that these stakeholders get
disenfranchised.
I'd like to hear the arguments of the potentially-disenfranchised stakeholders first hand. Is it mainly because it makes it harder to sell or use products that allow traffic snooping?
- matthewmacleod 12y agoOne obvious change here is that it would make CA-signed certificates mandatory for all HTTP2 web servers - is that really a situation we want?
- quicksilfer 12y agoThat doesn't have to be the case. You could still allow self-signage, with all of the security caveats that presents. Who knows. Maybe that arrangement could even spur a sorely needed push for a free certificate trust network and get rid of CA's entirely.
- rx4g 12y agoSelf-signed certs are much harder to get browsers to accept these days. The "I know what I'm doing" button and process are becoming ever more complex, and I wouldn't be surprised if they just start going away in favor of a list of trusted root CAs, which you may or may not be able to control as a user, depending on your browser. Which sucks. But anyway. StartSSL is one place where you can get a free cert for your website today (and yes, they charge for revocation, but revocation is pretty ineffective anyway). I got a free cert from them, but my mobile browser doesn't trust it, so I decided to shell out $10 for a cert that's more widely auto-trusted by browsers. Not a huge cost, IMO.
- rx4g 12y agoI can't speak for anyone else, but I certainly do. Regardless of the form of PKI employed, there's going to be a cost associated with validating the identity of the parties you're communicating with. For the average Joe, certs that require domain ownership validation are pretty cheap these days -- certainly on par with domain name registration fees. As with domain names, people need to just start treating it as a necessary cost of running a website. To be clear, I am far from a fan of X.509, but I'm not holding my breath for something better to come along (and be widely deployed) this decade. So let's use what we've got.
- idlewan 12y agoThose who don't have CA-signed certificates can still use HTTP/1.1, I don't think it's that big of a deal.
- quicksilfer 12y agoI'd like to hear why maintaining status quo for stakeholders should ever be a valid argument for a technology standard.
- akerl_ 12y agoBecause for a standard to actually become standard, you have to make it desirable for the people who you're trying to talk into switching to it.