The real death of HTTP isn't that HTTPS is being forced. That's good and bad but at least you can chose and it's HTTP underneath. The death of HTTP is "HTTP"/3 which is barely related to past HTTP protocols and doesn't even allow a choice. Eventually the megacorp browsers will drop real HTTP/1.1 support from their browsers for QUIC based transport. That will be the death of HTTP.
What's interesting about this doomsday scenario is it suggests that a few web browsers dictate the course of the www, not several billion websites. I'm betting that HTTP outlives me and goes beyond the time period I use the www. So far, so good. HTTP/1.1 pipeliing works better than ever. The www is faster than it's ever been and I can consume more web than ever before. I am generally unable to crash the web browser I…
RIP HTTP
31–40 of 131 posts
Re: RIP HTTP
#32HTTP belonged to a simpler time, the same way in some communities you don't lock the front door.
Re: RIP HTTP
#33My go-to HTTP-only endpoint is http://example.com . It should be usable for as long as IANA and the Internet as we know it exists.
Re: RIP HTTP
#34My go-to HTTP-only endpoint is http://example.com . It should be usable for as long as IANA and the Internet as we know it exists.
http://captive.apple.com
Re: RIP HTTP
#35We apparently still need http to detect wifi portals.
Re: RIP HTTP
#36Re: RIP HTTP
#37My go-to HTTP-only endpoint is http://example.com . It should be usable for as long as IANA and the Internet as we know it exists.
Re: RIP HTTP
#38HTTP is alive and well. Most people don't realise a lot of software/OS updates come through HTTP so that HTTP caching servers have an opportunity to do their thing.
But but... what abouts th3 securaitai?
The updates are signed. Tamper with them all you like.
Re: RIP HTTP
#39My go-to HTTP-only endpoint is http://example.com . It should be usable for as long as IANA and the Internet as we know it exists.
http://captive.apple.com
Re: RIP HTTP
#40The way I handle it is I have the captive portal DNS name in public DNS returning a private address. When I order the CA cert from my cert provisioner of choice, I'm able to pass all verification checks. I'd use LetsEncrypt if I could, but good luck getting that going on a Cisco Wireless LAN Controller.