3 ms·
I would say Snowden's legacy is the push to get HTTPS everywhere.
by commandersaki 6d ago
I would say Snowden's legacy is the push to get HTTPS everywhere.
- firesteelrain 6d agoThat’s true
- Lammy 6d agoWhich ironically makes the Internet more surveillable, because now every single connection has to hit some TLS-terminating origin and can't be cached at the edge of our own networks. Don't confuse security with privacy.
- judge2020 5d agoWhat??? The internet is only more concentrated because most people choose price and convenience over a foolproof level of security. The cost/effort required to surveil traffic in coordination with TLS-terminating CDNs is multiple orders of magnitude higher than the effort needed to throw some high-Tbps middlebox in an IX rack to siphon every packet passing through it.
- Lammy 5d ago> in coordination with TLS-terminating CDNs Not what I'm saying. No coordination is necessary. I'm talking about metadata, not encrypted contents — just the fact that you made some number of connections, at a certain time, from a certain network, to a certain network, in a certain order, with requests and responses of a certain size. It really doesn't matter what's inside. - https://kieranhealy.org/blog/archives/2013/06/09/using-metadata-to-find-paul-revere/ https://kieranhealy.org/blog/archives/2013/06/09/using-metad... - https://youtu.be/kV2HDM86XgI?t=1072 https://youtu.be/kV2HDM86XgI?t=1072 “First of all, David's description of what you can do with metadata […] is absolutely correct. We kill people based on metadata.” ― Former NSA and CIA director General Michael Hayden (2014)
- nl 5d agoSure, but hiding the contents provides a lot more value than hiding some parts of metadata. It's ridiculous to argue otherwise. It's true that general resources could be cached in some cases, but personalized information couldn't be (and yes was served over HTTP, not just HTTPS). > It really doesn't matter what's inside It certainly does matter what is inside, and it's trivial to think of cases where it does. Hiding that content is much much more valuable. > We kill people based on metadata. Sure, but they also kill people based on content.
- Lammy 5d ago> It's ridiculous to argue otherwise. I wholeheartedly disagree :) If you will refer to the “survivability onion”: https://en.wikipedia.org/wiki/Survivability#/media/File:Survivability_Onion.png https://en.wikipedia.org/wiki/Survivability#/media/File:Surv... Don't be there I am here → Don't be seen Don't be acquired You are here → Don't be hit Don't be penetrated Don't be killed One will note that it's called ‘HTTPS’ and not ‘HTTPP’ lol
- nl 5d ago> If you will refer to the “survivability onion” > I am here → Don't be seen My point is that you aren't. For example under the old HTTP only internet they could see you were visiting HN, who you were and what you published. Under HTTPS they see you are visting HN. It's strictly better except in cases of visiting highly popular data which was cached in public caches. These public caches were much less wide spread than you appear to believe (for example in Australia the Internode ISP tried one for a little while but abandoned it because of the problems with it serving info one logged in person to another - cache invalidation was frequently buggy) > One will note that it's called ‘HTTPS’ and not ‘HTTPP’ Not sure who that is aimed at but I didn't write HTTPP, and yours is the only mention of it on this page. > lol If you are going to lol you had better make sure you are correct about what you are laughing about....
- 5d ago
- mitxela 5d agoLet's be realistic, very few networks had speed-improving caches that weren't surveilled. Transparent proxying was most often used to inject malware and fourth-party ads, instead.
- jeroenhd 5d agoOf course it can. Just not without the user's knowledge and consent. Let the user load your CA and you can cache and repeat whatever you want. In practice, those caches were all done for malicious purposes, usually for injecting ads and selling tracking information through injected headers. Those shared caches were monitored just as strongly, if not stronger, by the people doing internet surveillance.
- commandersaki 5d agoCan't cache interactive content which is probably more invaluable than static. HTTPS is overall a massive win, which is why NSA wanted to surveil it in the first place.
- octoberfranklin 5d agoSo what? They have Cloudflare. "SSL removed here"