2 ms·
I also want to mention that several governments probably have large-scale tapping infrastructure to passively record Internet traffic. However, they like people
by schoen 1y ago
I also want to mention that several governments probably have large-scale tapping infrastructure to passively record Internet traffic. However, they like people not to pay attention to that or think about it (because, you know, we might try to protect ourselves or even try to get them to stop!). This is especially true when your communications cross national borders, as many governments have promoted a theory that normal privacy rules (that they might accept in other contacts) shouldn't apply at the border or outside of their territory.
HTTPS is a really important defense against this, but it's really hard to know when it worked or when it was relevant, because the wiretappers weren't announcing what they were doing and similarly don't usually announce when it's being thwarted.
There are lots of limitations there. For example, traffic analysis may sometimes allow identifying pairs of people who communicate with each other in low-latency ways like a real-time call, or possibly also those who communicate in a distinctive way in high-latency ways. It may also allow determining, for example, which Wikipedia page you looked at, because the pages are different sizes and contain different numbers of images, so the timing and volume of your browser communications could be distinctive depending on which page you browsed to. But, if you don't do the HTTPS part, then you're basically just saying "we're going to allow anyone who controls network infrastructure to permanently record 100% of all communications in an easily searchable way, if they so choose".