Re: HTTP is just fine
Aymeric Vitte <[email protected]>
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <[email protected]> |
Le 20/11/2015 12:35, Richard Barnes a écrit : > On Thu, Nov 19, 2015 at 8:40 AM, Hanno Böck <[email protected]> wrote: > >> > It's amazing how the same wrong arguments get repeated again and >> > again... >> > > +1000 > > All of these points have been raised and rebutted several times. My > favorite reference is: > > https://konklone.com/post/were-deprecating-http-and-its-going-to-be-okay > > > You might not break the current internet but its future. Example: https://bugzilla.mozilla.org/show_bug.cgi?id=917829 How do you intend to solve this? ie the case of an entity that just cannot have valid certificates and/or implements a secure protocol on top of an insecure one (ws here for Peersm project, the other party can be by design a "MITM" but we completely don't care per the secure protocol used, the MITM will not know what happens next)? Like WebRTC too, but there is an exception for that one, self-signed certificates are (by some luck) accepted. It's obvious that browsers will be used for new services involving those mechanisms in the future, like P2P systems as sketched here: https://mailman.stanford.edu/pipermail/liberationtech/2015-November/015680.html -- Get the torrent dynamic blocklist: http://peersm.com/getblocklist Check the 10 M passwords list: http://peersm.com/findmyass Anti-spies and private torrents, dynamic blocklist: http://torrent-live.org Peersm : http://www.peersm.com torrent-live: https://github.com/Ayms/torrent-live node-Tor : https://www.github.com/Ayms/node-Tor GitHub : https://www.github.com/Ayms _______________________________________________ dev-security mailing list [email protected] https://lists.mozilla.org/listinfo/dev-security