3 ms·
Random coffee shop / hotel / etc wifi owners and other users on the network will only know that you're reading nytimes.com, and not which particular section/art
by TurningCanadian 10y ago
Random coffee shop / hotel / etc wifi owners and other users on the network will only know that you're reading nytimes.com, and not which particular section/article.
- TurningCanadian 10y agoAnd your session cookie..
- semiquaver 10y agoSession cookies are transmitted as headers which are protected by HTTPS.
- TurningCanadian 10y agoSorry, I meant that as an additional reply to "If so, this change amounts to not protecting user privacy as much as insisting that only the NYT can monetize their users' privacy." The cookie is now hidden from the MITM. Before, not only could they see what pages you see, but they could login as you.
- hackuser 10y agoYes, that's assumed in what I meant. Vendors that track their users, such as Google and maybe the NYT, by implementing HTTPS are basically saying: We don't want to share that data with anyone else (e.g., 'random coffee shop / hotel / etc wifi owners'); we want to keep the monetization of our users' privacy to ourselves.
- nathan_f77 10y agoIt's actually very easy to figure out which article you're reading. I just did a little experiment for fun: https://github.com/ndbroadbent/nyt_privacy https://github.com/ndbroadbent/nyt_privacy The wifi owners can see that you're reading nytimes.com, but they can also see how much data was transmitted. All they need to do is look up the length of each article, and compare that with how much data the server returned. Of course, I'm not too worried about hotel owners. I can imagine this technique is already being used by a lot of governments around the world.