4 ms·
> you're more or less at the mercy of that network's administrator No, you're not. Sure there are additional risks but making broad statements isn't helpful wh
by detst 14y ago
> you're more or less at the mercy of that network's administrator
No, you're not. Sure there are additional risks but making broad statements isn't helpful when we're talking about connecting to a service with SSL.
> connect your MAC address to the Gmail address
How? Again, it's possible but Gmail works over SSL. That connection would have to be compromised to make any connection to your MAC and then they'd have to make a connection from your MAC to your personal identity.
- napoleond 14y agoSorry, I didn't mean to spread FUD. I don't think it's an exaggeration to say that the LAN admin would have a significant advantage relating your online and offline personae, though. Even the URLs you visit (not encrypted, even over SSL) tell a story.
- icebraining 14y agoThe URLs are definitively encrypted. Only the domains aren't, because of SNI[1]. [1]: https://en.wikipedia.org/wiki/Server_Name_Indication https://en.wikipedia.org/wiki/Server_Name_Indication
- weinzierl 14y agoThe URLs you visit over SSL are encrypted (http://stackoverflow.com/questions/499591/are-https-urls-encrypted http://stackoverflow.com/questions/499591/are-https-urls-enc...). DNS is requests are a different matter though and therefore the host part of the URL is visible if you don't take extra steps. Apart from that: If I buy hardware from e.g. Apple or Dell, do they keep a database that connects the MAC to my identity? I don't know.
- napoleond 14y agoThanks, you and icebraining just taught me something. I don't know why I thought the entire URL was exposed. As for the MAC database, it doesn't really matter. It would be easier to correlate the MAC address with security camera footage, for example. (I worked on a project for a local network security firm doing exactly that--don't worry, I wasn't doing the security end of things.)