Preferences

TLS certs use to be about Identity as much as they were about encryption. There was a pay wall to being able to have encrypted communications with clients that was the equivalent of a colonoscopy over fax machine. Today that takes the form of EV Certs. Let's Encrypt democratized encryption but not identity.

Going back back to HTTP would allow for communications to be monitored by any intermediary and would be a huge step backwards in terms of privacy. Advertisers or Adversaries wouldn't need to compromise the client or the server to track you. Just ask AT&T nicely or compell Cloudflare via secret warrant.

Anonymous encryption is essential to the freedom of communication.

Identity is a wholly different problem that should be solved without being tightly coupled to encryption. And at the end of the day it's still only as reliable as the host server.


This item has no comments currently.

Keyboard Shortcuts

Story Lists

j
Next story
k
Previous story
Shift+j
Last story
Shift+k
First story
o Enter
Go to story URL
c
Go to comments
u
Go to author

Navigation

Shift+t
Go to top stories
Shift+n
Go to new stories
Shift+b
Go to best stories
Shift+a
Go to Ask HN
Shift+s
Go to Show HN

Miscellaneous

?
Show this modal