2 ms·
Which is still sufficient information to narrow down to the set of applications developed by a single entity. And because this is being done over HTTP, anyone a
by Deathmax 6y ago
Which is still sufficient information to narrow down to the set of applications developed by a single entity. And because this is being done over HTTP, anyone along the network chain has visibility as well.
- chpmrc 6y agoAgreed, this should be sent encrypted, obviously. My point was that the intent here might not be to "snoop" on users, as even the author points out by comparing his analysis with what Jeffrey Paul's article reported ("[...] that’s quite an important difference on a privacy perspective") but likely to efficiently handle certificate revocation. Hopefully they will find a better way.
- intricatedetail 6y agoIt's called plausible deniability and it's how frog is being boiled slowly.