Live data from Hacker News

HTTP/2 and HTTP/3 explained

alexandrehtrb.github.io

151–155 of 155 posts

Re: HTTP/2 and HTTP/3 explained

#151

Earlier quoted context omitted.

> The risks when viewing public documents that don't require execution is minimal. If you’re living in a well developed country with strong privacy laws, you might have a point. But most of the people in the world don’t, and in many places simply looking at LGBT communities can land you in jail. Then there’s places like the U.S. with multiple states currently doing their level best to criminalise so much as thinking…

TLS doesn't hide destination address, if you connect to LGBT site whose IP is known, you land in jail anyway.

So we’re just going to ignore the fact that most websites these days are co-located on shared IP addresses, and there’s perfectly good ways of encrypting the TLS SNI header?

Re: HTTP/2 and HTTP/3 explained

#152

Earlier quoted context omitted.

Yes. And there's almost zero risk to such (ARP poisoning? dns poisoning? etc) MITM attacks when you turn off javascript and don't blindly execute all programs sent to you as an end user. The problem with MITM attacks is when you execute programs or exchange money or other private information. The risks when viewing public documents that don't require execution is minimal. That's my point. One use case "web app stores…

> The risks when viewing public documents that don't require execution is minimal. If you’re living in a well developed country with strong privacy laws, you might have a point. But most of the people in the world don’t, and in many places simply looking at LGBT communities can land you in jail. Then there’s places like the U.S. with multiple states currently doing their level best to criminalise so much as thinking…

Lets talk again the first time a US state based CA revokes a cert under pressure for an abortion clinic site being against some state's law. Then you'll really want that HTTP/1.1 back. If we go CA TLS only it just means there's a single point of failure/censorship. HTTP+HTTPS is robust from censorship in a way centralized CA HTTPS only can never be.

Re: HTTP/2 and HTTP/3 explained

#153

Earlier quoted context omitted.

cmd.exe is a terminal emulator and PowerShell is a fully-formed scripting language (that Windows desperately needed). This analogy doesn't work the way you think it does.

> cmd.exe is a terminal emulator Isn't Windows Console the (old) terminal emulator, with cmd.exe being just the command-line interpreter.

Yeah, conhost.exe is the old terminal emulator effectively (cmd.exe being a shell).

Before that, csrss.exe handled terminal emulation (which is why console windows weren't themable[1]).

[1]: https://devblogs.microsoft.com/oldnewthing/20071231-00/?p=23...

Re: HTTP/2 and HTTP/3 explained

#154

Earlier quoted context omitted.

TLS doesn't hide destination address, if you connect to LGBT site whose IP is known, you land in jail anyway.

So we’re just going to ignore the fact that most websites these days are co-located on shared IP addresses, and there’s perfectly good ways of encrypting the TLS SNI header?

I heard a rumor that GFW blocks ESNI outright.

Re: HTTP/2 and HTTP/3 explained

#155

Earlier quoted context omitted.

How about resolution? Color depth? Complexity of what is displayed? Last I checked my old commodore PET wasn’t rendering ray-traced 4K UHD graphics at 60hz… 60hz is pretty easy if all you are doing is a simple character buffer.

> old commodore PET wasn’t rendering ray-traced 4K UHD graphics at 60hz… Nor is my phone, yet newer apps are now struggling to render basic GUIs at 60hz.

Your phone has a higher resolution, a lower size, and a lower thermal footprint, and more battery life....
Post reply on HN