OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Eric Rescorla (ekrspeedy.rtfm.com)
Date: Sat Jan 06 2001 - 09:57:38 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    Ian Grigg <iangsystemics.com> writes:
    > SSL, OTOH, is a broken piece of engineering, because it
    > tried to solve something that doesn't matter in the real
    > world. The added piece of complexity, certs, increase
    > its cost by a couple of orders of magnitude. And thus,
    > it failed to achieve dominance, it is only used where it
    > has to be used, rather than used everywhere it could be
    > used.
    I don't think this assessment holds up in the real world. SSL *is*
    universally accepted. It's implemented in every browser and server and
    a large number of them have turned it on.

    Here's a good test: has your mother ever used SSH? I bet
    she's used SSL. I know both my parents have--though they probably
    don't know it.

    -Ekr

    [Eric Rescorla ekrrtfm.com]