Re: HTTP is just fine
Ben Bucksch <[email protected]>
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <[email protected]> |
Richard Barnes wrote on 20.11.2015 12:35: > https://konklone.com/post/were-deprecating-http-and-its-going-to-be-okay He's basically stating: 'OK, so HTTPS takes power away from the little man and centralizes power. BUT that's OK, because it's always been like that and it's inevitable. The web isn't what it used to anymore anyways, so who cares. Let's just accept that we lost control.' Not a strong argument. Remember that TLS was designed at a time when all crypto from Netscape had to be approved - in detail, design and code - by the US government. TLS is unnecessarily and *deliberately* centralized and puts trust in the center over mutual trust between parties. Because that's what it was designed to do. And now it's promoted as solution against government surveillance. I can see them smile. What an irony. TLS was designed to protect credit card numbers. Nothing more. It was *explicitly* stated that it cannot protect anything that cannot be valued with less than 1 million $ (if you have doubts, check you CA's contract). It was never designed to protect privacy or other human rights, just your Amazon book order. TLS is simply the wrong solution. Ben