Hacker News new | ask | show | jobs
by superkuh 1307 days ago
You're missing out on the fact that the de-facto standard which is disappearing is HTTP+HTTPS. Not one or the other. Together they provide security and choice. This is what I hope we all chose to continue supporting. I am not anti-TLS. I'm not even anti-CA TLS. I just think HTTP should be an option.

The only situations where HTTP has reason to be removed entirely are government/corporate/institutional sites with a genuine risk of MITM attacks on login/etc processes. For normal websites (ie, not web applications with accounts) created by humans this makes about as much sense as wearing a bullet proof vest while on the phone; yeah, you're more secure but... it's not actually helping.