4 ms·
In practice it very nearly does. Only IE plan to support plaintext HTTP/2, all other browsers will only support it over TLS. Opportunistic Encryption is still
by Lukasa 12y ago
In practice it very nearly does. Only IE plan to support plaintext HTTP/2, all other browsers will only support it over TLS.
Opportunistic Encryption is still on the table as well.
- byuu 12y agoThe one major advantage to TLS everywhere will definitely be avoiding mixed-content issues when eg you have a web forum and someone tries to embed an image on a non-TLS server into their post. Hopefully IE's choice to be the one non-TLS HTTP/2 supporter doesn't undermine this. Since this is just going to be how it is, I just hope we can do more to make setting up TLS easier for everyone.
- higherpurpose 12y agoAh, once again Microsoft is the one that supports less security than the other major companies. Microsoft needs to distance itself a bit more from law enforcement agencies.
- Lukasa 12y agoI got the impression that Microsoft is backing this because of pressure from large enterprises, which do not want to deploy TLS in their intranets. I don't believe IE will prefer plaintext HTTP/2 to TLS HTTP/2, and it will certainly deploy both. Put another way: I don't believe Microsoft is worse than Google in this regard.