3 ms·
> ...there may be other things valuable for sniffering such as your identity (e.g., cookie) or your browsing habits. And SSL should be used in those cases. I'm
by jkire 11y ago
> ...there may be other things valuable for sniffering such as your identity (e.g., cookie) or your browsing habits.
And SSL should be used in those cases. I'm not saying you should never use SSL, I just don't buy the idea that you need to encrypt everything. Due to all the unencrypted bits like the IP address and DNS (and SNI?), sniffers can already guess what domains you're visiting anyway. Encrypting in those gives nothing that signing the plain text wouldn't.
> ...MitM can easily insert ads in the page without a SSL connection
Not if the response is also signed. (Assuming clients actually checked the signatures of course)