3 ms·
I'm sorry and I know these kinds of posts are sometimes discouraged here on HN but do you have a eli5 for that or possibly some reading I could check out. Why w
by wurst_case 7y ago
I'm sorry and I know these kinds of posts are sometimes discouraged here on HN but do you have a eli5 for that or possibly some reading I could check out. Why would https everywhere allow advertisers to enhance their targeting?
- endymi0n 7y agoI see less of a conspiracy there and more a classic tragedy of the commons. If you make it harder for malicious parties to intercept, read and modify your requests, you automatically make it harder for security research and any beneficial purposes as well.
- TeMPOraL 7y agoOr simply, past some point, security and usability are enemies. It seems to be impossible in practice to tell whether a thing is being done by a fully-aware user, by a confused user, by user under duress, or by malware impersonating the user - so the standard approach to security is to simply kill off any feature that could even remotely be misused. Which essentially means any and all features that are not under full control of the service provider. One day soon someone will figure out that the right way to deliver any and all content is through an end-to-end, cryptographically secure server -> HTTPS -> NIC -> HDCP -> screen pipe. And then we'll all have TVs instead of PCs, but at least they'll be secure™.
- donmcronald 7y agoIt's the sum total of all that technology. If you want to filter content there are a few options: * Look at the actual content if it's HTTP. HTTPS prevents this. * Look at the DNS query to determine the domain. DoH prevents this. * Look at the SNI header to determine the domain. ESNI prevents this. * Look at the IP address to see where the traffic is going. However, this isn't fine grained enough, especially if the traffic is going to a CDN. * MitM with a self-signed CA. This is the hardest option. It's impossible on many devices (because you can't install a root CA) and a huge PITA to install a custom root CA on devices that support it. It's also much more invasive than the other options and makes it possible to accidentally log sensitive information. Right now a lot of devices ignore your network config and use 8.8.8.8 for DNS. At least with DNS as a separate protocol, you can block external DNS servers and most devices will reluctantly use your local DNS (which can be used to block ads and tracking). However, once DoH starts getting adopted, those devices (and many apps) will start to use it because you can't block HTTP(S). Literally all a network admin is going to see is a bunch of encrypted connections to CDNs (Cloudflare, Cloudfront, etc.). IMHO, even though it's sold as privacy tech, it's a huge loss for the average person that can spin up a DNS based ad-blocker right now. It's going to get to the point where you no longer have control over your own network. The huge tech companies and ISPs will control everything.