Re: HTTP is just fine

Ben Bucksch <[email protected]>
Newsgroups gmane.comp.mozilla.security
Message-ID <[email protected]>
Hanno Böck wrote on 19.11.2015 17:40:
> On Thu, 19 Nov 2015 17:00:31 +0100
> Ben Bucksch <[email protected]> wrote:
>
>> Adding TLS to a site is still major work. Added with the fact that I
>> can't even get IPv4 addresses for each web *host* (much less each
>> domain) anymore, it gets far more complicated.
> You don't need an IP for every Domain. That was true 15 years ago. It
> is not any more. The solution is called SNI and it is in every major
> browser since many years.

I *explicitly* did *not* speak of domains, but *hosts*. I can't even get 
an IPv4 for my *server* anymore.

> Are you aware of the efforts to mitigate these problems, namely CT and
> HPKP?

And which certs do people pin? Those of the CAs. For 3 months. That's 
the recommendations I read.

A "mitigation" is not a solution.

And that destroys the "integrity" element, too.

Ben
_______________________________________________
dev-security mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.