4 ms·
TLS specifically does not prevent a passive eavesdropper from telling what compressed video you’re watching. If they can drop a few packets and force you to reb
by brians 7y ago
TLS specifically does not prevent a passive eavesdropper from telling what compressed video you’re watching. If they can drop a few packets and force you to rebuffer, they can tell very quickly—plausibly faster than you can tell watching the video start!
- otterley 7y agoThat’s interesting. Do you have a reference to a working example?
- danielparks 7y agoHow does that work?
- nitrogen 7y agoDropping packets is not passive...
- Dylan16807 7y agoOkay so ignore that part. It's a tangent to the actual point.
- danielparks 7y agoCan you point us to some documentation? I’m having trouble seeing how this would work absent a huge vulnerability in TLS.
- Dylan16807 7y agohttps://pdfs.semanticscholar.org/2015/26efeb7206e2704b8db46985e4fcb0b93e55.pdf https://pdfs.semanticscholar.org/2015/26efeb7206e2704b8db469... http://cs.jhu.edu/~cwright/oakland08.pdf http://cs.jhu.edu/~cwright/oakland08.pdf https://www.blackhat.com/docs/us-14/materials/us-14-Niemczyk-Probabilist-Spying-On-Encrypted-Tunnels.pdf https://www.blackhat.com/docs/us-14/materials/us-14-Niemczyk... There's variation in the segment-to-segment sizes of video. Watching the stream of data, you can pretty easily find many of the segment sizes, and from there you just need a lookup table. Figuring out spoken language or which web pages are in packets is fuzzier but still viable.
- danielparks 7y agoAh, thanks. That makes sense.