Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Why is signed HTTP exchanges dangerous, and indeed, what are they?


https://github.com/ipfs/in-web-browsers/issues/121#issuecomm...

> Google Chome makes SXG indistinguishable from regular HTTPS, which breaks basic assumptions around how users understand the green padlock in location bar (aka "nobody but me and the Origin server can see the payload"). UX of regular HTTPS is reused as-is, pretending that end-to-end HTTPS transport was used with Origin from location bar, which is not true.

https://blog.intelx.io/2019/04/15/a-new-type-of-http-client-...

https://docs.google.com/document/d/1ha00dSGKmjoEh2mRiG8FIA5s...

> Big changes need strong justification and support. This particular change is bigger than most and presents a number of challenges. The increased exposure to security problems and the unknown effects of this on power dynamics is significant enough that we have to regard this as harmful until more information is available.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: