5 ms·
This sounds like a tempest-teapot scenario because he doesnt seem to know about http/2 which includes the feature TBL is ranting about. Instead, he comes off a
by dh997 11y ago
This sounds like a tempest-teapot scenario because he doesnt seem to know about http/2 which includes the feature TBL is ranting about. Instead, he comes off as fingerwagging at folks for doing something to stop-gap fix the web because the http RFC didnt include security from the beginning. Adding tls to http/1.x is impractical, utopian mythology because there's too much deployed to ever change until http/2 becomes widely deployed.
Instead of ranting, downplaying the EFF and others for improving the situation or wishing for the impossible, TBL missed the opportunity to support adoption of http/2, which might not be perfect (PHK mentioned rushed process and protocol complexity) but it has been touted to supersede http/1, https and spdy.
btw: there's also unauthenticated opportunistic encryption like tcpcrypt which works via server and client plugins.
https://en.wikipedia.org/wiki/HTTP/2#Encryption https://en.wikipedia.org/wiki/HTTP/2#Encryption
https://tools.ietf.org/html/rfc7540 https://tools.ietf.org/html/rfc7540