Hacker News new | ask | show | jobs
by belorn 4121 days ago
HTTP/2 could have mandated that it would only be used under a encrypted connection. It could have added opportunistic encryption.

The builders of technologies decided not to go that route. I wish they did, but we can't put all our eggs on the assumption that they will fix the situation for us.

1 comments

TLS does nothing if the site owners hand over data.

Also, HTTP/2 is a horrible mess already. Encrypted channels should not be part of it. They are something separate and should be specified separately.