Hacker News new | ask | show | jobs
by mtgx 3540 days ago
Exactly what I wanted to say. Why even bother if encryption is not included by default in the new protocol?
1 comments

Encryption is not a panacea. It's not a magic button that makes everything it touches "Secure!".
Indeed, but there is something to be said for sane defaults--look at the thread on HN a few weeks ago about SSH cipher defaults. Yes, TLS and the CA ecosystem has its faults, but my stance is that any chat protocol should be using auth and encryption, especially group chat protocols like IRC. I'm less upset now after seeing that the proposed spec for IRC 3.3 includes something similar to HSTS.