[Cryptography] NSA voting on TLS encryption at the IETF TLS WG
Ian g
iang at iang.org
Sat Jul 11 06:59:54 EDT 2026
On 09/07/2026 01:55, Peter Fairbrother wrote:
> Or why eg don't browsers support unencrypted and unauthenticated
> websites any more?
Back in the day, when I really cared about this stuff, we figured out
that TLS was approximately worthless if the browsers presented
unauthenticated web. SSL was worse [1].
So we started a pogrom on cleartext web & SSL. Not because of the
encryption but because of the certs. So that the Authentication built
into TLS had a half chance of actually mattering. It took about a decade
to reach the 80% mark and it was probably only due to LetsEncrypt that
it made it that far. Such is the lock on the industry by the cartel.
Having said that, this was a consensus position from people across many
camps, and therefore didn't see the resistance that was seen in for
example trying to face up to phishing.
iang
[1] https://financialcryptography.com/mt/archives/000472.html
More information about the cryptography
mailing list