[Cryptography] NSA voting on TLS encryption at the IETF TLS WG

Ian g iang at iang.org
Sat Jul 11 06:59:54 EDT 2026


On 09/07/2026 01:55, Peter Fairbrother wrote:
> Or why eg don't browsers support unencrypted and unauthenticated
> websites any more?

Back in the day, when I really cared about this stuff, we figured out 
that TLS was approximately worthless if the browsers presented 
unauthenticated web. SSL was worse [1].

So we started a pogrom on cleartext web & SSL. Not because of the 
encryption but because of the certs. So that the Authentication built 
into TLS had a half chance of actually mattering. It took about a decade 
to reach the 80% mark and it was probably only due to LetsEncrypt that 
it made it that far. Such is the lock on the industry by the cartel.

Having said that, this was a consensus position from people across many 
camps, and therefore didn't see the resistance that was seen in for 
example trying to face up to phishing.

iang

[1] https://financialcryptography.com/mt/archives/000472.html



More information about the cryptography mailing list