Skip to content

Comment on HTTPS Watchparent

Comments

The argument is that someone may not be able to audit TLS stack, not that someone may not be able to use TLS stack.

Requiring TLS forces people to include TLS stack, which enlarges trusted computing base a lot. Security depends on many things, but the size of trusted computing base is an important factor.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.