Hacker News new | ask | show | jobs
by liquidgecka 1051 days ago
Because at some point you will need to deprecate ciphers and when you do you don't want old clients to explode. The domain is the way you version connection requirements so you can support old clients with crappy ssl options without screwing up the security of new clients.