HTTPS Is Not Just TLS

Read Original

The article discusses the Python core team's debate on enabling HTTPS certificate verification by default, arguing it's essential for security. It explains that HTTPS is not just HTTP with TLS but implies a covenant of authenticity, and criticizes the practice of skipping verification. The author strongly advocates for backporting the fix to Python 2.7, even if it breaks insecure code.

HTTPS Is Not Just TLS

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser

Top of the Week