All hail EFF's new Encrypt the Web with the HTTPS Everywhere Firefox Extension.
A Personal Blog
by Michael Froomkin
Laurie Silvers & Mitchell Rubenstein Distinguished Professor of Law
University of Miami School of Law
My Publications | e-mail
All opinions on this blog are those of the author(s) and not their employer(s) unelss otherwise specified.
Who Reads Discourse.net?
Readers describe themselves.
Please join in.Reader Map
Recent Bluessky Posts- A BFD, folks: www.anthropic.com/news/stateme... February 27, 2026 Michael Froomkin
- I think you're having too much fun. But I'm enjoying it. February 27, 2026 Michael Froomkin
- Not worse than the alternative in the general election. February 27, 2026 Michael Froomkin
- So long as he caucuses right and Ds get the committee chairs that's already a lot February 26, 2026 Michael Froomkin
- The Conference of Catholic Bishops is... not playing around in this brief. www.supremecourt.gov/DocketPDF/25... February 26, 2026 Raffi Melkonian
Recent Comments
- KK Ho on Introduction
- Michael on Robot Law II is Now Available! (In Hardback)
- Mulalira Faisal Umar on Robot Law II is Now Available! (In Hardback)
- Michael on Vince Lago Campaign Has No Shame
- Just me on Vince Lago Campaign Has No Shame
Subscribe to Blog via Email
Join 51 other subscribers
i dunno, ssl is not trivial, server-side. insisting on it, all the time, will invariably increase load and break some sites that do automagical redirection (hotmail certainly, yahoo maybe, gmail probably not). IPv6 could in theory make this a moot point, but alas, it’ll get rolled out with widespread acceptance right around the 5th of Never.
I don’t think ipv6 has a lot to do with this (application support for ipsec? seriously??) but think this could be useful. I’m really not sure what’s at the end of the pipe and it may be the case that the endpoints are sufficiently widely distributed that computational load associated with SSL/TLS is largely a moot question. There are an awful lot of sites using unencrypted password-based authentication, and that needs to be protected (even though it won’t protect things like pop and imap).
Also, to the “5th of Never” comment, I’d probably go with the 3rd of Never – v6 support is already available on Google, Youtube, Facebook, and a bunch of other high-traffic sites. I work at a DOD-affiliated center and I’d guess the majority of my network traffic is transported over v6.
There are potentially some sort-of weird topological issues here (and getting back to the v6 thing, what *about* v6?) but on balance I’d say this is more good than bad, and that’s good.