Re: HTTPS, proxying, and all that...

>The issue described in the link is described as a MitM attack. 

Which is the only option available with HTTPS.

It is surprisingly more common than you'd think in $bigcorp settings.

>Anyway, I don't see how HTTP/2 could do any better than that without
>becoming some kind of cross-layer monstrosity.

It could offer per-hop encryption as an alternative to end-to-end
encryption, while keeping the user reliably informed about the
level of security.

