4 ms·
> you are now letting everyone know what possibly vulnerable packages you have. Erm, what? The number of people, who can listen to (much less — modify) your t
by altfredd 8y ago
> you are now letting everyone know what possibly vulnerable packages you have.
Erm, what?
The number of people, who can listen to (much less — modify) your traffic is very small. It is basically your ISP (who is supposed to offers you services in good faith, not spy on you) and a number of engineers, who maintain Internet backbone. That's far from "everyone". Some SSL evangelists make it sound like everyone's traffic is permanently broadcasted to everyone else in the world, but it is not.
As for "vulnerable packages", the most certain sign, that someone does not install security updates, is lack of traffic between them and update servers. But that's orthogonal to use of encryption.
- DoctorOetker 8y ago"everyone" in this context obviously means everyone on the path, and any attackers that have compromised nodes along the path. See the Belgacom hack by 5 eyes...
- monocasa 8y agoAnd I those attackers can still tell everything based on the target IP and the payload sizes.
- DoctorOetker 8y agothere is no proof that this is true in general, so it is worth trying to find 1) an inefficient way in order to 2) postulate an efficient way... for example, overlay onion routing, size blurring by appending random length random bits,... with oblivious transfer even the APT-server does not know what you downloaded (but that would require a large amount of information..., nevertheless oblivious transfer might still be a useful tool when used as a primitive, perhaps just to send a list of bootstrap addresses for p2p hosting of the signed files etc...)