Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> No, I am not going to do work on it, any work, at all.

Without HTTPS, the content can be replaced entirely. Last time it was JavaScript that DDOS'd github. If you don't want to serve content over HTTPS, then you don't care what your users receive. Just delete the site and they all get 404's instead, since you already admit that you don't care either way.

If it makes you feel any better, HTTP without HTTPS was a mistake we all made together. It should never have happened.



> If it makes you feel any better, HTTP without HTTPS was a mistake we all made together. It should never have happened.

Given that http predates SSL 1.0 by a few years, somewhat inevitable.


Given that HTTP without TLS can provide backwards compatibility while anyone and their dog is advocating for deprecating TLS versions and them being too complex for most people to maintain on their own, I respectfully disagree that plain HTTP was a mistake.


Seems ,like since inception internet protocols was designed with foreseeable security implications, Gnunet is project is attempting to solve this




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: