Re: HTTP is just fine
Ben Bucksch <[email protected]>
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <[email protected]> |
Hanno Böck wrote on 19.11.2015 17:40: > On Thu, 19 Nov 2015 17:00:31 +0100 > Ben Bucksch <[email protected]> wrote: > >> Adding TLS to a site is still major work. Added with the fact that I >> can't even get IPv4 addresses for each web *host* (much less each >> domain) anymore, it gets far more complicated. > You don't need an IP for every Domain. That was true 15 years ago. It > is not any more. The solution is called SNI and it is in every major > browser since many years. I *explicitly* did *not* speak of domains, but *hosts*. I can't even get an IPv4 for my *server* anymore. > Are you aware of the efforts to mitigate these problems, namely CT and > HPKP? And which certs do people pin? Those of the CAs. For 3 months. That's the recommendations I read. A "mitigation" is not a solution. And that destroys the "integrity" element, too. Ben _______________________________________________ dev-security mailing list [email protected] https://lists.mozilla.org/listinfo/dev-security