Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

> But this is not enough; we also need to work on opportunistic encryption, to be used for sites that do not use SSL today, without any certificates

That's exactly what this proposes!



No, not as far as I can tell. The linked document has two options for opportunistic encryption, one of which is without server authentication, but that does not mean without certificates. The draft http://tools.ietf.org/html/draft-nottingham-http2-encryption... also states that the certificates would be used, just not necessarily checked.

My issue with the use of certificates is that it would in practice probably mean required manual server-side configuration, which would be a barrier to adoption (even if self-signed certificates are allowed). I would prefer a certificate-less approach that is available by default and for all sites.

The proposal also requires HTTP/2.0 for opportunistic encryption, even though we could probably make it work with HTTP/1.x too.


Well, ignored certs would be functionally near-equivalent to no certs.

If implmentations ended up keeping some meaning for them, you could look at how most ssh server keys are generated - no configuration.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: