4 ms·
Yeah, I'm just thinking one could relax that policy--if there were actually a viable strategy for flagging sites, which there may not be. Unless you're tunneli
by jarrett 12y ago
Yeah, I'm just thinking one could relax that policy--if there were actually a viable strategy for flagging sites, which there may not be.
Unless you're tunneling SSL, you can't know that ngrok doesn't inspect your traffic. Promises of privacy that are based on the honor system aren't worth much, at least to me. I'm not at all attacking the honesty of the ngrok operator; I'm just stating a generality about security--one that applies regardless of how much you think you trust any particular actor. For two main reasons: 1) The actor may not be as good as you think, and 2) even a truly good actor can be compromised in a variety of ways.
Therefore, to me at least, a promise not to inspect traffic has little or no value. And if that promise has no value to users of ngrok, perhaps it could be relaxed in favor of protecting the long-term viability of the service.
That being said, the caveat stated above still applies. There's no point in relaxing the promise unless there exists a viable flagging strategy. And such a strategy may not exist, owing to the problems I described in my previous post.