Reply to post: Re: Dumb idea IMO..

Come in HTTP, your time is up: Google Chrome to shame leaky non-HTTPS sites from January

martinusher Silver badge

Re: Dumb idea IMO..

One of the more irritating things about modern software is that it just piles hack upon hack. The original purpose of the web was to serve information but the needs of e-commerce, advertising and so on made it imperative that it 'push' information to a user's desktop. This wasn't something that the protocol was designed to do so it just introduced security issues. The only way people can think of fixing the security issues is encrypting everything which carries the risk of holes being found in the encryption protocol (its never the actual coding that's the issue, its the way that its used is typically the weakness, and the more stuff that's encrypted (especially stuff where you happen to know the plaintext) the better the chance of finding a hole.

Instead of constantly patching and fudging this mechanism needs to be dealt with properly once and for all. We can start with CGI, a travesty (and a fruitful source of security issues), hit Javascript (a viable scripting language that's widely abused).....build something that works from the ground up. I'm prepared to sacrifice bells and whistles for something that works properly.....the question is, in this marketing driven world, whether everyone else is prepared to.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon