|By Lori MacVittie||
|September 30, 2016 01:45 AM EDT||
Yes, Lori has been reading the Internet again. And what she's been seeing makes baby Lori angry. It also makes this former test designer and technology editor cry. Really, I weep at both the excuses offered for such testing and the misleading headline.
I have read no less than two contrived comparisons of "HTTPS" and "HTTP" in the last two weeks purporting to demonstrate that secure HTTP is inarguably faster than its plaintext counterpart, HTTP.
Oh, if only that were true.
See, the trick is that both comparisons (and no doubt many more will follow) are comparing secure HTTP/2 with insecure HTTP/1.1. From the aforementioned comparison: "Plaintext HTTP/1.1 is compared against encrypted HTTP/2 HTTPS".
As we are all already aware, HTTP/2 itself is faster (by design) than HTTP/1.1 for a variety of reasons that have absolutely nothing to do with security. Multiplexing, ‘smart' headers, and a binary bitstream all combine to provide a faster and more efficient protocol, period. While it's likely the case that layering security (TLS or SSL) atop HTTP/2 will cause a slight degradation in performance (because math says it will), it's not enough to drive performance down the levels we are used to seeing with HTTP/1.1, even unsecured.
Unfortunately, these results are touting as inarguable proof that HTTPS is faster than HTTP. Which is simply not true. The argument against testing HTTP/2 secure against HTTP/2 plaintext is that browsers refuse to support HTTP/2 without security, and thus there is no way to perform such a test. So a test was contrived to pretend to illustrate the differences, but in fact does not do anything of the kind.
It's true that comparing secure HTTP/2 with insecure HTTP/2 would be passingly difficult, if not impossible. While HTTP/2 backed off its requirement for only secure connections and allows for plaintext, all the major browsers refused to support plaintext and have thus far only provided support for HTTP/2 over TLS/SSL. Even popular command line tools like curl refuse to allow insecure HTTP/2 connections. Which winds up making HTTPS the de facto standard, even though the specification doesn't. But that doesn't mean you can go ahead and compare the two and then make absolutely ridiculous claims based on that test that are disproven with simple mathematics.
See, let's pretend that a web page transferred via HTTP/2 plaintext took exactly 1.2 seconds to load. Now let's add TLS. The addition of TLS (or SSL for that matter) means there is more processing that goes on, specifically encryption and decryption of the data. Even if that takes only .3 seconds, it still means that HTTPS is a teensy bit slower than HTTP. Period. Math says so, and math is pure. It has no agenda, it doesn't care about the results, it simply says "here it is."
And math says if you do X and then add on Y you get Z, and Z will always be greater than X or Y.
I understand the desire to push folks toward HTTP/2, because it's faster and it's the first real "upgrade" we've had to HTTP in a really long time, but it takes time, especially when it requires a lot of upgrades and changes to infrastructure that will necessitate disruptions as everyone from app dev to ops to netops to security have to drop what they're doing and test, deploy, and test again. And that doesn't account for changes in modifying apps that have long been built around HTTP/1.1 and its protocol specification. HTTP/2 changes everything. And its impact spans the entire data center. While gateways mitigate the inherent difficulty and disruption stemming from migration, not everyone necessarily sees a driving need to hop on the HTTP/2 bandwagon.
The boost in performance organizations will see simply means HTTP/2 performs as its designers intended, with increased speed and efficiency. It means organizations should be planning on the app and network infrastructure upgrades necessary to migrate to support the new standard, whether that's through HTTP gateways or not. It doesn't mean that HTTPS is faster than HTTP.
Making demonstrably false claims to craft click bait like headlines regarding allegedly superior performance is simply unacceptable. Yes, you will almost certainly see a boost in performance if you're moving from HTTP/1.1 to HTTP/2, even with forced security. But that does not, in any world where logic and math exist, mean that HTTPS is faster than HTTP. If you want to help organizations, help them understand how to smoothly transition from the old to the new. Provide meaningful data for them to build a business case that enables them to upgrade to the latest and greatest. Provide them the means to show that the investment in moving from HTTP/1.x to HTTP/2 will pay off in the long run.
Offer guidelines and best practices, not punchy headlines and a buried lede.
Sep. 30, 2016 07:30 AM EDT
Sep. 30, 2016 07:15 AM EDT Reads: 2,239
Sep. 30, 2016 07:15 AM EDT Reads: 3,266
Sep. 30, 2016 07:00 AM EDT Reads: 3,464
Sep. 30, 2016 07:00 AM EDT Reads: 2,334
Sep. 30, 2016 07:00 AM EDT Reads: 1,506
Sep. 30, 2016 06:15 AM EDT Reads: 1,128
Sep. 30, 2016 06:00 AM EDT Reads: 1,260
Sep. 30, 2016 06:00 AM EDT Reads: 2,736
Sep. 30, 2016 05:30 AM EDT Reads: 1,281
While DevOps promises a better and tighter integration among an organization’s development and operation teams and transforms an application life cycle into a continual deployment, Chef and Azure together provides a speedy, cost-effective and highly scalable vehicle for realizing the business values of this transformation. In his session at @DevOpsSummit at 19th Cloud Expo, Yung Chou, a Technology Evangelist at Microsoft, will present a unique opportunity to witness how Chef and Azure work tog...
Sep. 30, 2016 05:15 AM EDT Reads: 1,847
Almost two-thirds of companies either have or soon will have IoT as the backbone of their business in 2016. However, IoT is far more complex than most firms expected. How can you not get trapped in the pitfalls? In his session at @ThingsExpo, Tony Shan, a renowned visionary and thought leader, will introduce a holistic method of IoTification, which is the process of IoTifying the existing technology and business models to adopt and leverage IoT. He will drill down to the components in this fra...
Sep. 30, 2016 05:00 AM EDT Reads: 1,884
As ridesharing competitors and enhanced services increase, notable changes are occurring in the transportation model. Despite the cost-effective means and flexibility of ridesharing, both drivers and users will need to be aware of the connected environment and how it will impact the ridesharing experience. In his session at @ThingsExpo, Timothy Evavold, Executive Director Automotive at Covisint, will discuss key challenges and solutions to powering a ride sharing and/or multimodal model in the a...
Sep. 30, 2016 04:45 AM EDT Reads: 673
Internet of @ThingsExpo, taking place November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA, is co-located with the 19th International Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading industry players in the world and ThingsExpo Silicon Valley Call for Papers is now open.
Sep. 30, 2016 04:45 AM EDT Reads: 4,719
I'm a lonely sensor. I spend all day telling the world how I'm feeling, but none of the other sensors seem to care. I want to be connected. I want to build relationships with other sensors to be more useful for my human. I want my human to understand that when my friends next door are too hot for a while, I'll soon be flaming. And when all my friends go outside without me, I may be left behind. Don't just log my data; use the relationship graph. In his session at @ThingsExpo, Ryan Boyd, Engi...
Sep. 30, 2016 04:45 AM EDT Reads: 1,411