Oddbean new post about | logout
 They’re moaning about people having to make sure their site works with TLS? Seems like a weird complaint. My issue is that TLS is an overcomplicated beast of a protocol (okay somewhat better with 1.3, but even still), which is the enemy of security, we have like 100 “roots of trust” in the form of CAs, most of which have a long history of being terrible, it relies on too many pieces of an increasingly huge stack, etc….