top | item 28099754

(no title)

ndkwj | 4 years ago

We must overcomplicate everything until there can only be one implementation of each standard

discuss

order

asddubs|4 years ago

okay, but being able to use only one SSL certificate for each IP fucking sucks

tialaramex|4 years ago

In particular, in the era before SNI support was widespread, your bulk host would charge extra to give you a dedicated IP address so that your HTTPS site worked. It's still an option at some bulk hosts today, you can have free HTTPS that works fine in every browser anybody actually uses or you can pay a few bucks extra so that it also works with the archaic system that one customer never updates.

jcims|4 years ago

Beyond that, it was absolutely essential to decouple address from identity in order to move the vast majority of sites and services on the Internet to TLS.

Somehow I’ve avoided gaining an understanding of the details of the SNI protocol, so i can’t comment on its quality, but the achievement it has enabled is fairly profound.

infogulch|4 years ago

Insert inevitable "this would be fixed if everyone switched to IPv6 already" comment here.

dane-pgp|4 years ago

^ Found the Google Chrome dev.