3 ms·
At least consumers still have https going for them I suppose? Or maybe ISPs are now more motivated to man-in-the-middle those connections to get to the data, un
by Asdfbla 10y ago
At least consumers still have https going for them I suppose? Or maybe ISPs are now more motivated to man-in-the-middle those connections to get to the data, under the guise of security or something?
- notheguyouthink 10y agoYea that was my main question during this. What can we do. I thought https made this near impossible unless they MITM it, which would be difficult no? Or is it easy? This is all the more reason we need to start encrypting all communication. All my hand built services (home bots, etc) need to start using tls for everything.
- cjcampbell 10y agoThree problems here. First being that the ISP is a permanent MITM. Second is that TLS will not protect the hostnames, which are sent in the clear so that servers can identify the correct certificate for a given connection. Likewise, DNS is not encrypted (though companies like OpenDNS do provide alternatives here).
- notheguyouthink 10y agoRegarding the MITM, more specifically i meant able to compromise HTTPS. If i sit between you and your https site, can i read all of your traffic? I know very little about the nitty gritty of HTTPS, so forgive my ignorance, but i thought the most i could do was try to pass off a custom key (ie, spoof the key authority), but then the signing done from the https site (say, https://google.com https://google.com) wouldn't be valid based on my bad key. How common is it to read full https data if you're a MITM?
- cjcampbell 10y agoIt's not likely that they would attempt active attacks to decrypt your TLS web traffic. I'd assume they won't be able to read the full contents of those sessions. STARTTLS on mail is a slightly different story, though I'm going to assume that most of the established compaines are smart enough fo avoid email snooping. You might, however, be surprised at how much you give away via the metadata associated with your web browsing.
- UncleMeat 10y agoYou don't need to compromise HTTPS. You need to get your cert onto the trusted list on the device. "As part of the setup for Comcast-Super-PlanTM please run this script" is enough to let your ISP terminate the SSL connection and restart it so they can read content. In the worst case, they can pay a company like Lenovo to stick their certs on devices on day 1.
- Operyl 10y agoThey can still correlate traffic going to specific IPs, DNS requests, and SNI information (since it's not encrypted, because the remote server needs to know what certificate to use). There's plenty of data to choose from.
- huxley 10y agoI don't believe SSL alone would protect you since ISPs would still have access to the DNS lookups, the fully qualified domain name of the server (which is sent in cleartext for SNI), and IP addresses for the person browsing, so there's still plenty of "meta-data" for them to sell. Maybe if you use a third party DNS service, but then you need to trust them.
- state_less 10y agoIs there TLS connections to DNS servers available for the major operating systems? edit: You're still broadcasting the IP you're connecting to, but it's still nice to close up this DNS lookup leak.