3 ms·
You understand that when using https an ISP only ever sees the hostname, not the rest of the URL, right?
by stevelosh 15y ago
You understand that when using https an ISP only ever sees the hostname, not the rest of the URL, right?
- freehunter 15y agoYes, I understand this. I don't see your point. Are URLs sensitive information? Hiding a URL is security through obscurity, I don't expect an outrage over obscurity being revealed. At least not from anyone who understands how security works.
- bad_user 15y agoThis is not about security, this is about respecting your privacy. There's a difference between: www.facebook.com ... and ... www.facebook.com/rebecca.some.name
- freehunter 15y agoBut doesn't the carrier see "1-555-123-4567" "Rebecca S. Name" "facebook.com" "123 Fake St, Springfield Ohiyamaude" "Visa XXXX-XXXX-XXXX-XXXX" ? Wouldn't they be able to put 2 and 2 (and 2 and 2 and 2 and 2) together to know who the traffic is coming from anyway?
- rmc 15y agoIf I were to watching YouTube over ssl, the carrier would not be able to tell what videos I watched, all they could know is that I went to YouTube. With http they could know what videos I watched. There are plenty of youtube videos that you might not want everyone to know you are watching, political videos, religious videos, how to do crossdressing, etc.
- marshray 15y agoYes, URLs can definitely contain sensitive information. There are no hard-and-fast rules about it (the web wasn't designed for privacy or security), but often web servers are configured to not log query string parameters for this reason.