Live data from Hacker News

Netflix now supports TLS 1.3

netflixtechblog.com

101–110 of 141 posts

Re: Netflix now supports TLS 1.3

#101
post #97
post #56

Can someone explain why this thread is full of people not caring about security? This article even goes over how TLS 1.3 is a perf improvement Have the anti privacy crowd come out in droves now that we have a public desire for contact tracing & there's a desire to scapegoat why netflix et al have reduced stream quality due to increased load? & HTTP is not an option. I for one enjoy my ISP not being able to inject ads…

You're probably running into the contrarian dynamic: https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que... . Your comment is a great example of the second wave: objections to the objections, getting upvoted to the top of the thread. (Edit: it's no longer at the top, see explanation below.) Comment threads don't represent the community view. They self-select for commenters who object to something. This is pa…

Neat, I've noticed this pattern in the past, but haven't ended up in this spot myself

What's the better way to play out this dynamic? Since there were three comments I didn't think it'd be optimal to spam by replying to all three individually. Maybe picking one to reply to would be better. I don't think downvoting is the right play, but ignoring may be

Maybe responding with agreement to the article, without objection to the objection

Re: Netflix now supports TLS 1.3

#102

I noticed they didn't explicitly mention why they feel the need to ensure authentication+confidentiality+integrity for their streams, given that the data they're dealing with is films and TV shows, rather than, say, payment details. As I understand it, they use HTTPS to prevent spying and data-mining by unscrupulous ISPs. It doesn't affect their DRM at all, which would work just as well over plain HTTP.

To prevent another Max Headroom incident?

Joking aside, Netflix's web page runs on a vast variety of devices from phones to smart TV's which don't have the same security profiles. You don't want someone to be able to inject a packet to your Netflix stream to pwn your TV.

Re: Netflix now supports TLS 1.3

#103
post #90

Earlier quoted context omitted.

> netflix et al have reduced stream quality due to increased load OT, but why am I still paying full price for less-than-full quality? Same with Amazon - why am I paying for two-day Prime shipping even though it's impossible to get that level of service right now? /rant

I'm fairly certain that neither Amazon nor Netflix promise you anything more than best effort on their streaming quality or delivery time. You can always cancel your contract with them if you don't like it.

Sure, but if I'm signed up for a 4K plan and Netflix has entirely disabled 4K, they cannot possibly provide me what I'm paying for.

Note: I'm not even sure they have disabled 4K, it's just an example.

Re: Netflix now supports TLS 1.3

#104
post #101
post #97

Earlier quoted context omitted.

You're probably running into the contrarian dynamic: https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que... . Your comment is a great example of the second wave: objections to the objections, getting upvoted to the top of the thread. (Edit: it's no longer at the top, see explanation below.) Comment threads don't represent the community view. They self-select for commenters who object to something. This is pa…

Neat, I've noticed this pattern in the past, but haven't ended up in this spot myself What's the better way to play out this dynamic? Since there were three comments I didn't think it'd be optimal to spam by replying to all three individually. Maybe picking one to reply to would be better. I don't think downvoting is the right play, but ignoring may be Maybe responding with agreement to the article, without objection…

Great question! It's better to reply, because then it at least won't get upvoted to the top of the thread, accruing mass and blocking fresh conversation. I think you're correct that it suffices to pick one to reply to, perhaps the most prominent one, or the one where the reply will be most interesting. I don't see any problem with downvoting something like https://news.ycombinator.com/item?id=22934379 as well.

The trouble with an indignant anti-crap comment is that it can't help but repeat the crap it's objecting to, because that's what it's about. Negation is a form of repetition. Crap subthreads tend eventually to get moderated by users, but that doesn't happen with their anti-crap counterparts. Usually those get upvoted to the top, since people love defending the unfairly criticized and we all respond to indignation. But then it sits there, choking out new discussion with metafumes.

The best way to counter bad comments is to post a good one—for example, a reflective comment about the specifics of the article, or a curious comment about something unexpected in it. This isn't always an option, though, because one doesn't always have something like that to say. I think responding to reflexive negativity with a pleasantly-worded objection can still be helpful—just not as a top-level comment.

Re: Netflix now supports TLS 1.3

#105
post #101
post #97

Earlier quoted context omitted.

You're probably running into the contrarian dynamic: https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que... . Your comment is a great example of the second wave: objections to the objections, getting upvoted to the top of the thread. (Edit: it's no longer at the top, see explanation below.) Comment threads don't represent the community view. They self-select for commenters who object to something. This is pa…

Neat, I've noticed this pattern in the past, but haven't ended up in this spot myself What's the better way to play out this dynamic? Since there were three comments I didn't think it'd be optimal to spam by replying to all three individually. Maybe picking one to reply to would be better. I don't think downvoting is the right play, but ignoring may be Maybe responding with agreement to the article, without objection…

I'm imagining some kind of heterarchical mode of comment threading where you can refer to n parent comments for your reply. Could that ever work for semi-mainstream discussion formats? The interface could perhaps work like hashtags, but instead of generic topics, you tag your desired parent comments. Similar to a multi-quote on a non-threaded (chronological only) forum topic.

Re: Netflix now supports TLS 1.3

#106
post #90

Earlier quoted context omitted.

I'm fairly certain that neither Amazon nor Netflix promise you anything more than best effort on their streaming quality or delivery time. You can always cancel your contract with them if you don't like it.

Sure, but if I'm signed up for a 4K plan and Netflix has entirely disabled 4K, they cannot possibly provide me what I'm paying for. Note: I'm not even sure they have disabled 4K, it's just an example.

Seems a bit like when a congested campus has a "space not guaranteed" paid parking program, and you opted for a tier that includes VIP spaces. The VIP spaces near your building are currently being restriped so you can't use them. Should you automatically get bumped to the non-VIP tier since it no longer brings you value? No, you stay on that tier because theoretically it offers you the VIP spaces at other buildings (like the 4K streams in places that aren't collaborating with Netflix on decongestion strategies).

Re: Netflix now supports TLS 1.3

#107
TLS 1.3 has been out for a while now, and always promised performance improvements (for example, see this Cloudflare article from Sep 2016: https://blog.cloudflare.com/introducing-tls-1-3/). I wonder why Netflix is only getting to it now? Even if some clients didn't support it yet, seems like they could still introduce support on the server side?

Re: Netflix now supports TLS 1.3

#108
post #91

It is interesting to see the experiment results with 7%-8% improvements in media rebuffers with just moving from 1-RTT to 0-RTT. Wonder if they ever considered having only one layer of encryption instead of two (TLS and DRM). Would that save more CPU and hence avoid media rebuffers lot more?

DRM is required by the people they licence video from. I imagine that they wouldn't do it if they didn't have to. (They might still do it to their own content but I don't see what they gain by doing it for someone else's)

By now I have only heared about (and experienced) the downsites of DRM. Are there any good arguments for it / casestudies that show any reduction in piracy?

Re: Netflix now supports TLS 1.3

#109
The elephant in the room is Youtube, which supports only (when last I checked) TLS 1.0. My OpenSSL is configured to fail connections below 1.3, but evidently Firefox bypasses that with its own TLS.

If they support TLS at all, why not 1.3? Do they have some dodgy hack that avoids a performance cost in 1.3 that is not in 1.0? Or is it just sloth?

Re: Netflix now supports TLS 1.3

#110
post #56

Can someone explain why this thread is full of people not caring about security? This article even goes over how TLS 1.3 is a perf improvement Have the anti privacy crowd come out in droves now that we have a public desire for contact tracing & there's a desire to scapegoat why netflix et al have reduced stream quality due to increased load? & HTTP is not an option. I for one enjoy my ISP not being able to inject ads…

Agreed. I've been blocking HTTP (on port 80) accross my network and I reroute all DNS traffic to a pihole configured to use DoT. At this point in time there is really no reason to let anyone see plain text traffic. A few things are whitelisted but the handful of things that break aren't necessary anyway.

How do you manage the cleartext SNI over 443?
Post reply on HN