Re: HTTP is just fine

Ben Bucksch <[email protected]>
Newsgroups gmane.comp.mozilla.security
Message-ID <[email protected]>
Richard Barnes wrote on 20.11.2015 12:35:
> https://konklone.com/post/were-deprecating-http-and-its-going-to-be-okay 

He's basically stating:
'OK, so HTTPS takes power away from the little man and centralizes power.
BUT that's OK, because it's always been like that and it's inevitable.
The web isn't what it used to anymore anyways, so who cares. Let's just 
accept that we lost control.'

Not a strong argument.


Remember that TLS was designed at a time when all crypto from Netscape 
had to be approved - in detail, design and code - by the US government. 
TLS is unnecessarily and *deliberately* centralized and puts trust in 
the center over mutual trust between parties. Because that's what it was 
designed to do. And now it's promoted as solution against government 
surveillance. I can see them smile. What an irony.

TLS was designed to protect credit card numbers. Nothing more. It was 
*explicitly* stated that it cannot protect anything that cannot be 
valued with less than 1 million $ (if you have doubts, check you CA's 
contract). It was never designed to protect privacy or other human 
rights, just your Amazon book order.

TLS is simply the wrong solution.

Ben
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.