Sujet : Re: Maximalism Is A Better Word
De : ram (at) *nospam* zedat.fu-berlin.de (Stefan Ram)
Groupes : comp.miscDate : 03. May 2024, 12:49:29
Autres entêtes
Organisation : Stefan Ram
Message-ID : <HTTP-20240503124224@ram.dialup.fu-berlin.de>
References : 1 2 3 4 5
Ian wrote or quoted:
https is about lock-in and security theatre. Go look how many root CAs
are in your browser, and tell me none of them will ever issue certs to
bad guys, accidentally or otherwise.
With HTTP, it's a cakewalk for the client-side to analyze traffic
and suppress unwanted content. Insofar as HTTPS makes such measures
more difficult, it can actually reduce security to a certain degree.
Moreover, HTTPS could engender a false sense of security.
(As you wrote.)