Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

There are ways to do encrypted web that don't require a corporation to approve your website every 90 days. If Firefox would change it's release binary's build so the http/3 lib linked accepted self-signed certs the problem would be almost entirely mitigated while still retaining the 100% encrypted web (assuming trust on first use is acceptable to you). But these things aren't going to happen when everyone keeps ignoring and downplaying the implications of HTTP/3 support as shipped now and how it creates a handful of content approval gateways like WEI.

When HTTP/1.1 is a thing of the past and Firefox won't load any endpoint without CA TLS on HTTP/3 then the fact that there are only a handful of corporate entities you can get a TLS cert from means they'll be an even more tempting target for those that wish to apply pressure and restrict access to whatever topics they don't like. It wouldn't be the first time a CA has been pressured to drop a site and it certainly won't be the last if things go this way.

Additionally, it significantly increases the complexity of setting up visitable personal website. There are packages for acme2 and some CAs that can hide this complexity but it is there and does break. It acts as a roadblock to what I see as one of viable contributors to keeping the web open: self hosting.

But again, I brought it up because the original linked article suggests Mozilla would never accept something as bad as WEI. With the way FF HTTP/3 is implemented they already have done something similar in outcome. So I do think we need to make noise about WEI (and HTTP/3).



Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: