Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't get what this is supposed to prove. That my browser doesn't allow websites to declare what encryption they use? I am pretty sure there's a point to all of this, but please let me (and my browser) choose which encryptions I want to trust.

Is this a spec violation or something?

 help



Isn't the idea that the server and client should agree on a common subset? Here, the server's subset is very small, but not esoteric – so then surely it's the client that's lacking in features?

Yeah but I don't want Chachacha, I prefer AES. If you can't do AES, I'm not interested in the website :)

Precisely.

Fix the browser.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: