logoalt Hacker News

bawolffyesterday at 5:57 PM1 replyview on HN

Its not like its just tptacek with this take, i would say its the majority view in the industry.


Replies

indoleringyesterday at 6:08 PM

That doesn't make it correct. Imagine if someone had said, "We don't need to secure HTTP, we'll just rely on E2E encryption and trust-on-first-use". I would really like it if we had a way to automatically cryptographically verify non-web protocols when they connect.

But there is no money in making that a solution and a TON of money in selling you BS HTTPS certs. There is a lot of people spreading FUD about it. It's a shame.

show 1 reply