💾 Archived View for rawtext.club › ~sloum › geminilist › 001862.gmi captured on 2020-09-24 at 01:35:39. Gemini links have been rewritten to link to archived content

View Raw

More Information

-=-=-=-=-=-=-

<-- back to the mailing list

Mercury

Case Duckworth acdw at acdw.net

Wed Jun 24 15:26:59 BST 2020

- - - - - - - - - - - - - - - - - - - 

I think Mercury is a bad idea, at least for now, when Gemini is still very young and not established (or just established). For one thing, TLS was the main reason solderpunk even began thinking about an alternative to gopher (see gopher://zaibatsu.circumlunar.space:70/0/~solderpunk/phlog/why-gopher-needs-crypto.txt), and it's really the most important part of the protocol. Specifically the concerns over censorship, traffic modification, PGP key transmission, etc. I think removing TLS (or some kind of crypto) is a bad idea for that reason.

If you don't want to use TLS, use gopher. Gemini isn't trying to be everything for everyone -- it specifically mentions that it's *not* trying to supplant gopher or http, and it's trying to be a *new* protocol, built from the ground up with modern sensibilities. Mercury is a step backward in that regard.

As far as http, https (cf.

As long as the spec specifies both the "with TLS" and "without TLS
bits", and as long as most client/server authors agree to support
both, there shouldn't be any ecosystem split -- again, same as what
happened with http and https
Phil

) -- remember how much work was put into the public education part of looking to the little green lock at the address bar of browsers, and how long it took for most of the web (even now, not all of it's https) to switch to https? I'm not even really a developer and I remember seeing headline after headline, blogpost after blogpost, begging authors to switch to https -- and even now, it's a patchwork.

I have to use an extension like HTTPS Everywhere to make sure that a web page doesn't load some assets in the clear while I'm on a secured page! While gemini doesn't have that *particular* issue, it'll still be confusing for people casually browsing to know when/if they're moving to an insecure channel from a secure one or vice-versa.

Best,Case (acdw)