← Back to context

Comment by bawolff

4 hours ago

Its not like its just tptacek with this take, i would say its the majority view in the industry.

That doesn't make it correct. Imagine if someone had said, "We don't need to secure HTTP, we'll just rely on E2E encryption and trust-on-first-use". I would really like it if we had a way to automatically cryptographically verify non-web protocols when they connect.

But there is no money in making that a solution and a TON of money in selling you BS HTTPS certs. There is a lot of people spreading FUD about it. It's a shame.

  • > But there is no money in making that a solution and a TON of money in selling you BS HTTPS certs

    Ah yes, because lets encrypt is rolling in the $$$$.

    • Mark Shuttleworth paid for his ride to the space station by selling HTTPS certs.

      The sad thing is that Mozilla and others have to spend millions bankrolling Let's Encrypt instead of using the free, high assurance PKI that is native to the internet!

      4 replies →