|
|
|
|
|
by lucideer
1251 days ago
|
|
> I can send encrypted content over that insecure channel that only some receiver could decrypt and read. We've tried this approach with email and has not resulted in a world where I can easily send secure emails to anyone I know. Even setting aside the problem of inconsistent clients, you're asking for a world where every server re-invents wheels & you haven't even begun to think about solving for authentication (which is a very hard problem even with TLS) |
|
Of course it's easier to pay for a certificate from a certification authority that maintains the infrastructure, and no, Letsencrypt is free only on the issue side, but maintaining HTTPS has its warts (for example: renew the certs every 3 months!)
but the problem is not HTTP, HTTP in the hands of people who know what they are doing is completely okay, if browsers ban HTTP I predict an explosion of protocols like Gemini or something similar
A lot of low power devices don't need or can't handle HTTPS and there's no problem if what they do doesn't need security nor identity verification.
Meanwhile it's baffling that we are pushing for internet non-public non-state-run identity authorities, while in UK, Japan, Russia, USA and many other countries such an authority don't even exist for real people...