4 ms·
Why bother asking DDG itself when traffic can be intercepted and logged at their ISP?
by AlexMax 13y ago
Why bother asking DDG itself when traffic can be intercepted and logged at their ISP?
- JimJames 13y agoIIRC HTTPS would encrypt your data from your ISP.
- wcchandler 13y agoUntil PRISM subpoenas DDG and gets their private keys -- after which they can decrypt the SSL traffic.
- JoshTriplett 13y agoNot necessarily possible even with the private keys. If you use an SSL cipher with ephemeral keys, such as the DHE_* or ECDHE_* family of ciphers, then an eavesdropper with a recorded but not MITMed conversation cannot decrypt it even with the server's private SSL key. See http://vincent.bernat.im/en/blog/2011-ssl-perfect-forward-secrecy.html http://vincent.bernat.im/en/blog/2011-ssl-perfect-forward-se... for example.
- faddotio 13y agoWhat's preventing the government from coercing DDG to start log collections at their end, and then sealing it with a gag order?
- thrownaway2424 13y agoWhich of course they do not. Google uses ECDHE_RSA. DDG uses RSA. ixquick, "the world's most private search engine", uses RSA. Bing does not even offer https.
- jonknee 13y agoGoogle does pin their keys in Chrome though, so they know if there is a MITM (and they have, Chrome's certificate pinning led to DigiNotar's downfall). It's a non-scalable hack, but definitely a good one for the largest search engine and a leading email provider to be able to provide.
- betterunix 13y agoYour ISP probably has these installed on every one of their racks: http://www.wired.com/threatlevel/2010/03/packet-forensics/ http://www.wired.com/threatlevel/2010/03/packet-forensics/
- siddboots 13y agoThat's why you should https everywhere. https://www.eff.org/https-everywhere https://www.eff.org/https-everywhere
- deleted 13y ago[deleted]