Second, if it's private, surely you can just use your own Certificate Authority, instead of paying a tax to be listed on someone else's Certificate Authority.
Second, if it's private, surely you can just use your own Certificate Authority, instead of paying a tax to be listed on someone else's Certificate Authority.
Also, HTTPS with a public CA just works on most systems, whereas IPsec requires Client configuration. It's still easier to roll out than switching from IPv4.
For personal or experimental things, I may use a local CA, but getting certificates for the internal subdomains of my company is trivial when you already got a public domain on a Server that's capable of using DNS-01 challenges.
Enabling HTTPS is just way easier than actually ensuring you can trust your local network. Many real-life middle-class companies start out with just having a network and not thinking about security at all. Some companies may even have untrusted internal networks by choice by allowing BYOD.
Either write your own code or choose your dependencies more carefully.
PCI compliance among many other regulatory issues. You will be required to show that data is not only encrypted at rest but is encrypted through your entire transport chain regardless of any physical security. The threat model assumes that an attacker is able to temporarily access network resources undetected and can use simple sniffing tools to egress sensitive data. This will not be optional.
Are you suggesting that regulations make it so that everything should be a slow and inefficient https webapp?
trick question: you can't
even the network links between hosts in a single rack in a DC can be vulnerable
unless it's in your home, it's not trustable
They require your fingerprints for entry and everything is heavily monitored.
You can even get a stealthy cage if you don't want anyone to be able to see what kind of network equipment you have.
there was this whole thing with edward snowden a few years ago, maybe you remember?