3 ms·
This doesn't work with the push to HTTPS. Either you use proxy connect, and Privoxy is no better than /etc/hosts blocking. Or you'd rely on the proxy's poorer
by Tobu 12y ago
This doesn't work with the push to HTTPS.
Either you use proxy connect, and Privoxy is no better than /etc/hosts blocking. Or you'd rely on the proxy's poorer and slower implementation of TLS. Certificate verification will suffer (no certificate pinning, no certificate blacklist, no OCSP stapling, no way to verify incomplete chains), no SPDY, no sunsetting of bad ciphers or bad protocols.
- pekk 12y agoIs there some reason in principle why you can't constructively MITM yourself without using piles of Javascript in the browser?
- euid 12y agoThere is no reason in principle, and you can even do it for kicks.[1] The only issue here is a practical one, as the parent poster described: from an end-user perspective, browsers do SSL/TLS better than ad-blocking proxies. [1]: An example from the other side of the coin: http://www.wired.com/2010/03/packet-forensics/ http://www.wired.com/2010/03/packet-forensics/