I'm not cool with that. I feel like a ton of HTTP requests are for very simple html pages that don't require any kind of login/security and the overhead of HTTPS is of no benefit.
I'm not cool with that. I feel like a ton of HTTP requests are for very simple html pages that don't require any kind of login/security and the overhead of HTTPS is of no benefit.
The real question is whether or not this will proliferate and to what extent.
Meaning you'd have to pay a tax to put your site on the net when everyone only uses SPDY.
Like I said, they're just discussions and currently the tide is against us.
I would imagine that the overhead of fetching data from a database, talking to the network, etc, would outweigh the cost of doing an SSL handshake if you bundle your resources correctly.
Not that I share that opinion. I think the whole world needs to move on SSL, even though it's kinda broken in the current method where a select few companies make a crazy killing selling their SSL certs (although there are cheap alternatives).
If it's a simple HTML site - who cares? A simple HTML site with < 100KB of content and < 15 resources to fetch isn't a bit deal anyways. Two or three seconds to a user on a mobile device isn't unreasonable.
If the site is more complex, the SSL handshake most likely isn't your bottleneck.
I found this[1] to be an interesting read.
[1]: http://www.semicomplete.com/blog/geekery/ssl-latency.html