4 ms·
I have to sound like a fatalist but today's software resembles yesterday's malware. It does not matter if you're running a general purpose computer if you have
by antattack 6y ago
I have to sound like a fatalist but today's software resembles yesterday's malware. It does not matter if you're running a general purpose computer if you have no control over 'your' applications or even OS (Windows 10).
In addition, new privacy features such as HSTS and DNS over https, ESNI, etc degrade what control you had even further stopping you from even knowing what data gets out of your network and when.
- lxgr 6y ago> In addition, new privacy features such as HSTS and DNS over https, ESNI, etc degrade what control you had even further stopping you from even knowing what data gets out of your network and when. Inspecting these, on a machine you control, is still 100% possible – I do it all the time. Are you proposing we should go back to plain HTTP and DNS just to make tinkering easier? I'd argue that that would come at the expense of the vast majority of users.
- forgotmypw17 6y agoHow do you know what you're inspecting is actually what is contained inside the request?
- fomine3 6y agoWireshark is OSS, any problems?
- forgotmypw17 6y agoThat does not mean you can verify that the encrypted content contains what is shown to you and only that. Let's not pretend that it does.
- moonshinefe 6y agoAnd how do you know some nefarious hacker didn't mess with your far easier to mess with unencrypted stream?
- forgotmypw17 6y agoIt's much easier to inspect at multiple points, and I know what to expect coming down the pipe. There are multiple threat models, and having different options helps in different situations. It's also not realistic for me to try to figure out what's going on inside an SSL or TLS library. I'm OK with TLS being the default, but I believe in always providing a plaintext option. TLS also introduces compatibility and accessibility issues. With regards to GPC specifically, requiring TLS cuts off access for a huge population of about 20 years' worth of older devices which work fine otherwise. There are many, many situations where plaintext ability has allowed me to access my own resource where requiring TLS would have caused it to fail, and I'm certain there are many more which I cannot even anticipate ahead of time.
- deleted 6y ago[deleted]