logoalt Hacker News

nlyesterday at 4:30 AM3 repliesview on HN

Sure, but hiding the contents provides a lot more value than hiding some parts of metadata.

It's ridiculous to argue otherwise.

It's true that general resources could be cached in some cases, but personalized information couldn't be (and yes was served over HTTP, not just HTTPS).

> It really doesn't matter what's inside

It certainly does matter what is inside, and it's trivial to think of cases where it does. Hiding that content is much much more valuable.

> We kill people based on metadata.

Sure, but they also kill people based on content.


Replies

Lammyyesterday at 4:41 AM

> It's ridiculous to argue otherwise.

I wholeheartedly disagree :)

If you will refer to the “survivability onion”: https://en.wikipedia.org/wiki/Survivability#/media/File:Surv...

                 Don't be there
     I am here → Don't be seen
                 Don't be acquired
  You are here → Don't be hit
                 Don't be penetrated
                 Don't be killed

One will note that it's called ‘HTTPS’ and not ‘HTTPP’ lol
show 1 reply
ShinyLeftPadyesterday at 4:59 AM

if you visit wikipedia.org/whistleblowing, what exactly value is there from hiding content but force revealing you visited it, making sure it can't be retrieved from a cache within your organization/school network?

and doesn't pervasive tls termination mean that Cloudflare/etc sees plaintext anyway? do we really believe that palantir isn't tapping into that?

i can imagine just a few scenarios where hiding content on the web actually achieves something. mainly stuff like webmail, web chats, banking.

show 1 reply
Melatonicyesterday at 5:08 AM

Doesn't encrypted DNS make a lot of that metadata moot ?

And of course the additional options available

show 1 reply