Funny SSL setup. Explanation from here <a href="https://news.ycombinator.com/item?id=49133598">https://news.ycombinator.com/item?id=49133598
> Oh, certain browser will not work with this blog if it cannot negotiate ONLY for Cha-Cha/Poly. It's by design as a showcase of why that particular web browser refuses to do that.
I assume the "particular web browser" is Chromium, which won't load it on any OS I've tried. On Windows, Firefox and the built-in curl.exe also refuse to connect.
I don't get what this is supposed to prove. That my browser doesn't allow websites to declare what encryption they use? I am pretty sure there's a point to all of this, but please let me (and my browser) choose which encryptions I want to trust.
Isn't the idea that the server and client should agree on a common subset? Here, the server's subset is very small, but not esoteric – so then surely it's the client that's lacking in features?
Nnnes · · focus · HN ↗
Funny SSL setup. Explanation from here <a href="https://news.ycombinator.com/item?id=49133598">https://news.ycombinator.com/item?id=49133598
> Oh, certain browser will not work with this blog if it cannot negotiate ONLY for Cha-Cha/Poly. It's by design as a showcase of why that particular web browser refuses to do that.
I assume the "particular web browser" is Chromium, which won't load it on any OS I've tried. On Windows, Firefox and the built-in curl.exe also refuse to connect.
dark-star · · focus · HN ↗
Is this a spec violation or something?
gspr · · focus · HN ↗
dark-star · · focus · HN ↗