3 ms·
"Another lesson is that privacy defenses don't need to be perfect. Many researchers and engineers think about privacy in all-or-nothing terms: a single mistake
by textmode 8y ago
"Another lesson is that privacy defenses don't need to be perfect. Many researchers and engineers think about privacy in all-or-nothing terms: a single mistake can be devastating, and if a defense won't be perfect, we shouldn't deploy it at all."
This "all-or-nothing" perspective is rampant on www forums discussing computer topics and certainly HN is no exception. It is particularly acute in any discussions of "privacy" or "security".
There are countless examples.
Earlier this week the topic of SNI rose again to HN's front page.
A minor percentage1 of TLS-enabled websites require SNI. An unfortunate side effect of SNI is that it makes it easier for third parties to observe which websites users are accessing via TLS because it sends domainnames unencrypted in the first packet.
Forum commenters will thus argue because there are other, more difficult means for some third parties to observe these domainnames, e.g., through traffic analysis, that the unencrypted SNI is therefore not an issue worth addressing.
All-or-nothing. If the privacy achieved by some proactive measure is not "perfect" then to these commenters it is worthless.
But the HN front page reference suggested otherwise: It was an RFC describing how the IETF is taking a proactive measure, trying to "fix" SNI, encrypting it to prevent third parties from using it in ways detrimental to users.
There is an easier proactive measure. The popular browsers send SNI by default, even if the website does not require it. The default behaviour is to accomodate a minority of TLS-enabled websites at the expense of all users, including those who may not be using this minority of websites.
To make an analogy to fingerprinting, imagine sending 17 unique identifiers with every HTTP transaction when, say, only 5 are actually needed. The all-or-nothing perspective adopted by forum commenters would dictate that it makes no sense to reduce the number unless the number can be reduced to zero.
Amongst the security folks there is a concept sometimes called "defense in depth". Commenters in discussions about security often agree there is no such thing as "perfect" security and they cannot rely on a single, "silver bullet". They must use multiple tactics.
Is privacy somehow different? There are many tactics users can take that, cumulatively, can make things more difficult for the data collectors.
1 Survey of websites currently appearing on HN
Number of unique urls: 367
Number of http urls: 43
Number of https urls: 324
Number of https urls requiring SNI: 38
Number of https urls requiring correct SNI: 26
"Requiring correct SNI" means SNI must match Host header.
Summary
One can fetch 286 of the 324 https urls currently posted on HN with a HTTP client that does not send SNI.
An additional 12 can be retrieved by sending a decoy SNI name that does not match the Host header.