Also, it completely cuts out "legacy" devices, basically anything more than 5 years old.
The Web is once again splitting into AOLized mainstream and "indie underground" that you have to make an effort to access.
Also, it completely cuts out "legacy" devices, basically anything more than 5 years old.
The Web is once again splitting into AOLized mainstream and "indie underground" that you have to make an effort to access.
That 'third party' is one of the recognized 'certificate authorities'.
But the OPs point is by going https, you don't have a choice, you have to pay the certificate tax.
If you need https on the public internet you need a trusted cert.
I.e *.int.mycorp.com, but not www.mybank.com
Browsers don’t let me do that, it’s either app or nothing. X509 name constraints aren’t great either and don’t give me, the browser operator, the power.
I don't think they would even know the option exists.
I can recommend the docker image made by linuxserver in particular [0]. Makes Https a (tax free) breeze.
Want a NAS box for sharing family files/photos or some other IoT device at home? Just set yourself up some other device to run the docker image, get your self a certificate from LetsEncrypt and then... install it on the NAS box? How does that happen?
So, to summarize: one more way for the browser maker to control what the user can and cannot access without jumping through hoops.