Did you know that yesterday, August 23, 2013, was the birthday of the World Wide Web? Today it is exactly 22 years old and one day after its official announcement by its creator Sir Tim Berners-Lee.
Many things have happened since then, and one of the most disruptive was the revelation at its 21st, of the actions of the US secret services. The year marks the collapse of the myths about government monitoring of communications. They are no longer myths! Now there is evidence, and we are beginning to grasp the massive scale of the US ambition for global communications surveillance.
The Internet Engineering Task Force is a group of engineers who research, make recommendations, and provide standards for how various Internet services can work better.
One of these services is also the Hyper Text Transfer Protocol (HTTP) which defines how web browsers and servers on the Internet should communicate with each other.
A working group of the IETF recently met in Berlin to discuss the design of HTTP 2.0, the first update of the most fundamental internet protocol since 1999, Government surveillance of the internet was one of the first items on their agenda.
Speaking to the Financial Times, an IETF team member, Mike Belshe, said:
There was a complete shift in the way people perceive the world … not using encryption on the internet today can be considered a matter of life and death
From Belshe's comment one can understand that the discussion during the conference moved onto topics related to government surveillance and the use of encryption.
The version of HTTP in the current version 1.1 does not provide encryption by default. The encrypted HTTP protocol, known as HTTPS, requires more computational power, is slower and more difficult to create than plain HTTP.
The IETF's response to the threat of surveillance is simple. There must be “fair power” between you and the website you use, so that each side requires encryption, reports Sophos's Nakedsecurity.
Their proposal appears to have broad support from the team, and therefore there is every reason to believe that it will be implemented in the HTTP upgrade for version 2.0.
This, of course, will radically change the relationship between browsers and websites.
In the future, all websites will need to be able to provide encryption.
There is, of course, a very serious issue. The group's proposal concerns the confidentiality of your information, during its transfer and not once the information has already reached the website. If the website in question cooperates with the NSA and provides them with the encryption keys, then the secure HTTP protocol in version 2.0 can now be considered a utopia.
The positive thing in this whole story is that some people are looking for alternative solutions. We are sure that solutions to such issues do not appear after a single meeting.
Sir Tim's baby has grown and is constantly changing. Browser application developers compete for better suggestions. Perhaps eventually some will prioritize personal life privacy.
