3 ms·
They can log the domain you connected to, not the URL you visited
by hackcasual 10y ago
They can log the domain you connected to, not the URL you visited
- jvdh 10y agoAlthough with most TLS implementations they will see the size of your transfers, thus still giving away which URL you visited....
- mi100hael 10y agoIdea: HTTP server module that appends a minimal amount of hidden random garbage data (as a comment or similar) to each response so no two responses have the same fingerprint.
- moonlighter 10y agouser btown answered that elsewhere here in this thread: "https://github.com/technion/mod_randpad https://github.com/technion/mod_randpad (an Nginx module that injects padding as a comment into returned HTML documents) is likely the correct layer to add random padding; the performance hit would be negligible."
- tyrust 10y agoIf this is the first (and only) time someone visited the domain around the time of a leak, it may be a little suspicious.
- UnoriginalGuy 10y agoThen use public WiFi.