4 ms·
HTTPS improves security even for a static site because it prevents an ISP or middleman from injecting ads (or worse) into the page. It also increases privacy b
by ViVr 4y ago
HTTPS improves security even for a static site because it prevents an ISP or middleman from injecting ads (or worse) into the page.
It also increases privacy because the contents of the traffic can not be observed by third parties.
- marpstar 4y agoRight, but for a static site that’s publicly accessible, even HTTPS leaks the requested URL, any listener can go fetch that page themselves to see the contents.
- dmitrygr 4y ago> even HTTPS leaks the requested URL It does not. In the olden days the host name was leaked, but with SNI even that is gone. Anything past the first "/" is never and was never sent in plaintext in HTTPS
- cperciva 4y agoMost public web sites leak information about page accesses to anyone who can count bytes.
- teaearlgraycold 4y agoWhat kind of attack are you describing?
- cperciva 4y agoCount how many bytes of TCP traffic you see. Measure the size of each web page on the (public static) website.
- fmajid 4y agoThe host name is still leaked, SNI is not encrypted and ESNI is still not mandatory in TLS 1.3.
- 2h 4y ago> host name was leaked, but with SNI even that is gone nope, you can still see it perfectly fine: https://tlshello.agwa.name/ https://tlshello.agwa.name/ please don't spread misinformation.
- snowwrestler 4y agoHTTPS does not leak the requested URL to servers between the client and the server.