Maybe you didn't understand it?
Simplicity is a good reason to avoid HTTPS, also freedom and economy.
30% of internet is still HTTP.
100% of non-stupid internet is still HTTP.
Security is not needed in the base layer. You can superpose it.
Maybe you didn't understand it?
Simplicity is a good reason to avoid HTTPS, also freedom and economy.
30% of internet is still HTTP.
100% of non-stupid internet is still HTTP.
Security is not needed in the base layer. You can superpose it.
$ curl -I 'http://datatracker.ietf.org/doc/html/rfc2289'
HTTP/1.1 301 Moved Permanently
Location: https://datatracker.ietf.org/doc/html/rfc2289How far down the road of uniform waste of energy have we not gone when public specifications are encrypted.
After 4 years of HN defending Googles war on HTTP, these are the arguments I'm still met with.
I think this is the end of the road for me on HN.
I did.
>Maybe you didn't understand it?
I did, but it is only for protecting passwords where HTTPS protects the privacy and integrity of every request and response.
>Simplicity is a good reason to avoid HTTPS, also freedom and economy.
If it's so simple that it is insecure I would say that it is too simple. HTTPS helps with freedom and the economy because people no longer have to trust their network providers to be good actors. They can shop knowing their orders are private and their payment information is secure.
>30% of internet is still HTTP.
This is questionable, but most people don't use that many HTTP sites. 97% of the time people spend on the web is spent using https [0]. The web is trying to get rid of HTTP. Bruesky adding support for HTTP is just introducing unnecessary tech debt.
>100% of non-stupid internet is still HTTP.
I'm not sure what you mean by this considering how ubiquitous HTTPS is.
>Security is not needed in the base layer. You can superpose it.
Which is what HTTPS does. It's built on the insecure layer of UDP for HTTP/3 and TCP for the previous versions.
[0] https://transparencyreport.google.com/https/overview?hl=en
Ubiquitous in corporate hell? Try humans doing real work, they don't use HTTPS.
No HTTPS forces you to comply. If you make your own security on top of HTTP it's optional.
“Security is optional” is not a valid approach these days.
This is just a worse version of HTTPS. It provides no way to share the password with the host securely for your first connection with them.
>Ubiquitous in corporate hell?
Look at the site I linked most people are using HTTPS.
>If you make your own security on top of HTTP it's optional.
Which is a problem since people running sites may not invest in security. By banning HTTP you raise the security of the entire platform.
Google wants you to need HTTPS, that is what they sell.
From Chrome to GCP.
OTPs is not going to prevent governments, internet service providers, cafe owners etc from being able to intercept traffic and determine exactly what a user is posting. Which is not something anyone should want from a social network.
With OTP you can easily encrypt your data so nobody can read it inflight over HTTP.
I guess you need to have the creativity to extend the link knowledge with encrypting the data with the OTP.
Certificates are a scam.
My solution which is convoluted and relatively insecure if you have a persistent MITM is to require a password change that you can encrypt with the old password, then the MITM has to remember the old password to know the secret.
But you are right that OTP only are safe after the secret has been shared. Just like all crypto including HTTPS and SSH.
HTTPS is _not_ more secure in any way. The lock icon is an illusion.
As for the technical reasons:
- Big-ints are not trivial in js.
- DNS is centralized.
OTP is about authenticating clients, using a preshared secret established by unspecified means.
They’re completely different things. It’s like you’re comparing Apple (the company) and Orange (the city in NSW, Australia).
Cleartext HTTP is bad for various reasons, one of which is that pervasive monitoring is an attack: https://www.rfc-editor.org/rfc/rfc7258.html.
It's also quantum safe for eternity.