|
|
Log in / Subscribe / Register

Security quote of the week

Security quote of the week

Posted May 13, 2015 15:47 UTC (Wed) by gerv (guest, #3376)
Parent article: Security quote of the week

I wrote a response to another critical article, where I cover some of the misunderstandings Lauren shows here. It kind of feels like he got out of bed on the wrong side, as well. Digging through all that, his problem seems to be that switching to HTTPS is hard. Well a) people are making it easier, b) old sites which don't use newer web features will continue to be viewable, and c) China's Great Cannon, plus other ways that intermediaries can nefariously interfere with your non-encrypted connection, mean that HTTPS everywhere needs to be the future.

Also, he says we're all stick and no carrot. Is withholding a new web feature from HTTP, and having it be HTTPS-only, a stick or a carrot in his mind? In one sense, it's a carrot - what you never had, you still don't have. In another, it's a stick - there's often no technical reason it couldn't be HTTP as well, that's Mozilla's choice. I think, on balance, it's a carrot, but if he disagrees, perhaps that's why he thinks we're all stick.

Gerv


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds