6 ms·
http://arstechnica.com/security/2014/07/the-nsa-thinks-linux-journal-is-an-extremist-forum/ http://arstechnica.com/security/2014/07/the-nsa-thinks-linux...
by briansmith 12y ago
http://arstechnica.com/security/2014/07/the-nsa-thinks-linux-journal-is-an-extremist-forum/ http://arstechnica.com/security/2014/07/the-nsa-thinks-linux...
- omni 12y agoHTTPS does nothing for anonymity, though, right? It's only for protecting the actual content being transmitted? If so, there is no sensitive content being exchanged between a user and a static page that doesn't support login or anything.
- scrollaway 12y agoHTTPS protects metadata as well (to a large extent).
- briansmith 12y agoAggregating the content of the web pages you have read can be used to deduce your identity, and/or the content of the web pages can be used to select you for targeting, like in the article I linked to above. For example, let's say you wrote a blog post about fixing a configuration issue for touchpad issues on a ThinkPad X1 Carbon on Ubuntu 12.04. Imagine that a passive MitM saved the IP address of everybody who read that blog post in a database. Then, if an "interesting" person is known to be a ThinkPad X1 Carbon owner that uses Ubuntu 12.04. They can use that list of IP addresses of readers of that specific blog post to help narrow the search for the possible locations (via geo-IP) of that user. Right now it is pretty easy to distinguish which webpage on your blog the reader is reading through traffic analysis, even when HTTPS is being used. But, people are working on things that make that traffic analysis more difficult.