|
|
Log in / Subscribe / Register

It's only partially true

It's only partially true

Posted Jun 19, 2011 21:52 UTC (Sun) by kleptog (subscriber, #1183)
In reply to: It's only partially true by khim
Parent article: WebOS: the other Linux-based mobile platform

IMHO the big mistake with SSL was conflating the encryption with authentication. Sometimes indeed you trust the network enough (local LAN) enough not to misroute your packets, but you just don't want the bits to go unencrypted over the wire. With SSL the only way to achieve this is a self-signed certificate.

I think browsers should start recognising this use case and have a mode where they don't have the padlock, coloured URL bars, etc but still encrypt everything and don't complain. Make it look like normal HTTP. Add a cache to check the certificate against the previous one and you're all set.


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds