4 ms·
This isn't really true. The wholesale networks are operating at speeds that make this kind of sniffing impractical. I'm not saying they don't ever siphon traffi
by davidu 7y ago
This isn't really true. The wholesale networks are operating at speeds that make this kind of sniffing impractical. I'm not saying they don't ever siphon traffic for LEO or other reasons, but not for privacy-violating/ad-targeting reasons. DO probably is running 40gbps alone with each transit provider, plus sending traffic over peering circuits, so it's just way less practical.
So what you are suggesting isn't actually true, and it's hardly hypothetically even possible.
- leetbulb 7y agoTotally agree and I considered the shear throughput making it impractical. And while it's impractical, my point is that it's still possible, and maybe even practical in the future.
- kingosticks 7y agoMaybe I misunderstand by why is this considered impossible? Network processors read data from a packet, make decisions based on that, and then rewrite arbitrary parts of the packet. All on the fast path. This sounds doable if you had the custom firmware that did that. It'd just be a huge waste of money considering your very, very expensive network box.
- kingosticks 7y agoAhh so maybe it's because the packet, once out of the VPN and heading to it's destination, is (normally - it is 2019 after all!) TLS encrypted so you can't just modify the payload like I said. Fair enough.