But they're claiming it will require overhauling their infrastructure and cost money to do -- not that it's impossible to support, or that TLS 1.3 will "be illegal" if their demands are not met (this is just nonsense and 100% FUD on part of your comment, honestly -- and I say that as someone who thinks highly of your work). Furthermore there's no clear evidence TLS 1.2 will be deprecated anytime soon, so these people have years to sort out the details with their vendors to have replacements in-flight. Banks have money and connections. They'll survive this and evolve.
In any case, they could have made their concerns available earlier to the standards body. Like, over two and a half years ago (RSA key exchange was removed in early 2014). This is hardly the fault of "cyberlibertarians" or whatever, this is just these people being out of touch. The alternative here would be that these guys get to butt into the standardization process and demand changes at the very last moment, after years of work, with no negative impacts or consequences for them -- for what is ultimately a small portion of the overall internet.
Why would we want that? It completely undermines the authority of the IETF and the entire point of a standards process if "really important" people can just completely railroad it and demand changes on a whim with no consequences to themselves. Frankly, completely ignoring the actual content of the request, this alone is pretty bad behavior on their part.
Why we should worsen the security of billions of people, and introduce complexity into a vital internet protocol, so that those dorks can have slightly higher profit margins -- I dunno. Designing a security protocol is hard enough. If they didn't want to pay attention to the conversation, and now want to cry their pockets will take a hit -- well, maybe they'll learn and be more proactive next time and save themselves some cash.
> Who wins if browsers refuses to connect to web-banking which operates inside the boundaries of the law ?
Nobody ever said TLS 1.3 would be illegal for banks, that browsers are going to immediately drop TLS 1.2 after this (both of these two being a requirement for your prediction to be true -- lol, and also completely asinine) making it refuse to connect to a "law abiding bank", or that moving to TLS 1.3 would be literally impossible for them forever and can't be solved.
This is just complete FUD dude, c'mon. Unless you're actually interested in the answers to completely nonsense hypotheticals made up out of thin air, I guess...
In any case, they could have made their concerns available earlier to the standards body. Like, over two and a half years ago (RSA key exchange was removed in early 2014). This is hardly the fault of "cyberlibertarians" or whatever, this is just these people being out of touch. The alternative here would be that these guys get to butt into the standardization process and demand changes at the very last moment, after years of work, with no negative impacts or consequences for them -- for what is ultimately a small portion of the overall internet.
Why would we want that? It completely undermines the authority of the IETF and the entire point of a standards process if "really important" people can just completely railroad it and demand changes on a whim with no consequences to themselves. Frankly, completely ignoring the actual content of the request, this alone is pretty bad behavior on their part.
Why we should worsen the security of billions of people, and introduce complexity into a vital internet protocol, so that those dorks can have slightly higher profit margins -- I dunno. Designing a security protocol is hard enough. If they didn't want to pay attention to the conversation, and now want to cry their pockets will take a hit -- well, maybe they'll learn and be more proactive next time and save themselves some cash.
> Who wins if browsers refuses to connect to web-banking which operates inside the boundaries of the law ?
Nobody ever said TLS 1.3 would be illegal for banks, that browsers are going to immediately drop TLS 1.2 after this (both of these two being a requirement for your prediction to be true -- lol, and also completely asinine) making it refuse to connect to a "law abiding bank", or that moving to TLS 1.3 would be literally impossible for them forever and can't be solved.
This is just complete FUD dude, c'mon. Unless you're actually interested in the answers to completely nonsense hypotheticals made up out of thin air, I guess...