Live data from Hacker News

Spying on HTTPS

textslashplain.com

111–120 of 121 posts

Re: Spying on HTTPS

#111
post #110
post #99

Earlier quoted context omitted.

I was also going to speak about the descriptive and prescriptive approaches to languages, and then dropped my paragraphs because it was not clear to me whether OP acknowledged that singular they was a thing in English. I decided to consider that they effectively acknowledged singular they. By taking a prescriptive approach (telling how people should speak English), maybe singular they can be deemed invalid in English…

> About politics and languages. Politics are constantly shaping the language. This is not new. It's part of the natural evolution of languages. Politics are not inherently bad neither. We don't have slaves anymore in most countries, thanks to "politics". > Actually, I find politics is actually too vague a word, and some people seem to invoke it as a bad thing, saying that we should focus on technical matters when the…

I've grown accustomed to singular they, and I've actually joined a group of people for a week and using singular they was pretty common, and felt way more natural than what I expected. I guess this is a question of habit. Grammar is fine, and singular they would not be the only singular pronoun using the forms "are" and "were" for verb "to be": "you" also does.

Though you are far from being alone to dislike it. You might be interested by RMS's take on this: https://stallman.org/articles/genderless-pronouns.html

tl;dr: he argues that singular they feels wrong to him, and argues in favor of a gender neutral pronoun "pers", derived from "person". I like the idea, though I haven't seen it used anywhere and would not easily use it.

Re: Spying on HTTPS

#112
post #67
post #15

> monster in the middle (MITM) That’s not what it stands for. There’s nothing sexist about using an acronym the same way everyone else does.

Eric answers the point in the comments: "recognizing that the MITM is neither male, nor human at all". Personally, I suspect you are missing humour, and being over-sensitive, and making an incorrect assumption that it had anything to do with being PC.

are you kidding me that you really believe that it had nothing to do with being PC

Re: Spying on HTTPS

#113

Earlier quoted context omitted.

Your attempt to force your personal blend of newspeak onto the world has no place in tech nor in this discussion. Please leave your gender politics activism out of an interesting technical discussion that affects us all. Besides being pointless and stupid, it only adds noise to the debate.

Discussions should get more civil over time, not less. GP never mentions gender in their post, but in terms of politics, it seems to me that this entire thread is a political conversation. It's certainly not technical -- a technical person would not care about whether someone used the term "monster" or "man", since: a) it changes literally nothing about the technical details of the attack. b) everyone understands wha…

well what is more accurate? A man in the middle or a monster in the middle? Last computer conference that I visited, there were a lot of Men, some women but no monsters.. The same Pattern i observed in the last 15 years. So I think Man in the Middle is pretty much more accurate.

Re: Spying on HTTPS

#114
post #109
post #92

Earlier quoted context omitted.

I was thinking about singular they and its derivatives: their, theirs, them. Plural they is also gender-neutral, but its usage is not new nor controversial. Defending the use of gender-neutral pronouns was not my point, but since you ask what purpose they would serve, here are some reasons I can think of (and this answer is not limited to English): - to avoid having to specify or think about the gender(s) of the refe…

Plural they is pretty new in wide-spread usage? I usually just stick with generic "he" until I know otherwise; i.e. if a scientist found something, I don't really care whether he has ... I'm not sure I get the idea of referring to a known person as "they", and this is at best a controversial issue bound very tightly to one side of the political aisle. A side with which I do not align. I guess I probably wouldn't ever…

I'm not in an English-speaking place, so I can't say how often it is spoken and for how long it has been, but I see it everywhere on HN and in other parts of the web.

It seems that it is more accepted in GB than in the US [1] : “Garner's Modern American Usage (2nd ed., 2003) recommends cautious use of singular they, and avoidance where possible because its use is stigmatized. [...] Garner suggests that use of singular they is more acceptable in British English [...] and apparently regrets the resistance by the American language community: "That it sets many literate Americans' teeth on edge is an unfortunate obstacle to what promises to be the ultimate solution to the problem.”

Singular they seems prescribed in the US too, by The Chicago Manual of Style at least since 1993 for instance [1], and proscribed by others.

There are many possible reasons people would use singular they, I'm not sure we can put them in an homogeneous political group.

It seems generic he is losing acceptance, to the point I wouldn't comfortably use it [2]. It probably depends on the place though.

I would kindly invite you to reconsider using singular they instead of generic he, but this sure is controversial and I'm no one to tell anybody how to speak, and I would not want to neither. And when something about the language feels weird… well, it just feels weird. Languages are very personal and intimate.

I personally tend to rephrase sentences to avoid they, but use it when doing so is too inconvenient.

Thanks for the interesting discussion :-)

[1] https://en.wikipedia.org/wiki/Singular_they#Acceptability_an... (already cited in another comment of mine)

[2] https://en.wikipedia.org/wiki/Singular_they#Prescription_of_... (I know, always the same link ;-))

Re: Spying on HTTPS

#115
post #77

Ok, dumb question. If apparently any kind of technique to intercept an HTTPS stream makes security experts frown, how are you actually supposed to inspect them if you have a legitimate reason? (e.g. monitoring unusual behavior of your own system) Or is the security best-practice to just trust any app not to upload my contact list?

> how are you actually supposed to inspect them if you have a legitimate reason? By shoving your middlebox somewhere anatomically improbable. > monitoring unusual behavior of your own system Anything that tries to connect to the internet for a reason that you didn't both understand and ask for in advance is malware. > Or is the security best-practice to just trust any app not to upload my contact list? Yes. That is i…

> Anything that tries to connect to the internet for a reason that you didn't both understand and ask for in advance is malware.

So, everything?

Re: Spying on HTTPS

#116
post #110
post #99

Earlier quoted context omitted.

I was also going to speak about the descriptive and prescriptive approaches to languages, and then dropped my paragraphs because it was not clear to me whether OP acknowledged that singular they was a thing in English. I decided to consider that they effectively acknowledged singular they. By taking a prescriptive approach (telling how people should speak English), maybe singular they can be deemed invalid in English…

> About politics and languages. Politics are constantly shaping the language. This is not new. It's part of the natural evolution of languages. Politics are not inherently bad neither. We don't have slaves anymore in most countries, thanks to "politics". > Actually, I find politics is actually too vague a word, and some people seem to invoke it as a bad thing, saying that we should focus on technical matters when the…

> I don't believe it is incumbent upon me to alter the manner in which I speak and write for the convenience of another.

It absolutely is incumbent upon you to show people respect in a workplace or school setting. That means not calling Black people the N-word, or mocking Asian accents, or deliberately using the wrong pronouns for trans people.

> grammatical horror

English is already full of them, one more won't do any harm.

> that "they" as a singular simply feels clumsy and unnatural when spoken.

Not once you get used to it.

Re: Spying on HTTPS

#118
post #69
post #68

Earlier quoted context omitted.

Isn't that one of the reasons for DNS over HTTPS, which is being rolled out now[1] in some browsers? You can keep your ISP from seeing/intercepting/replacing DNS requests. 1: https://support.mozilla.org/en-US/kb/firefox-dns-over-https

There is no 90% or 95% neither with TLS nor with DoH. There are still IP addresses, OS-specific data in IP packets, response sizes, traffic patterns, SNI, active probing data, etc. ISPs can get so much stuff on you, you really should use a VPN if you don't trust your ISP.

ISPs aren't the NSA, and the NSA has no issue watching your VPN egress.

SNI is probably the most critical here, and it is getting opportunistic encryption.

Threat modeling. Do it.

Re: Spying on HTTPS

#119

Earlier quoted context omitted.

> FUD. Why should we want "behaves exactly as the browser does", when browsers (in fact, mostly Google's) are in fact turning against their users? To avoid introducing vulnerabilities, the way lots of antivirus MITMs do, for example. Like it says in the rest of your quote. > Especially Google's, because that's one of the ways you can still block ads and modify pages to have them displayed as the user(-agent) wants, w…

Extensions are very much a better tool for that. The idea that browser vendors are going to slowly cripple them so that they’re no longer an effective blocking tool is… wrong Did you not see this at all? https://news.ycombinator.com/item?id=20044430 Don’t. You're certainly displaying your allegiance to Big G...

Now that's paranoid.

Re: Spying on HTTPS

#120
post #69

Earlier quoted context omitted.

There is no 90% or 95% neither with TLS nor with DoH. There are still IP addresses, OS-specific data in IP packets, response sizes, traffic patterns, SNI, active probing data, etc. ISPs can get so much stuff on you, you really should use a VPN if you don't trust your ISP.

ISPs aren't the NSA, and the NSA has no issue watching your VPN egress. SNI is probably the most critical here, and it is getting opportunistic encryption. Threat modeling. Do it.

ISPs rely on DPI equipment vendors, which do all those things. And no, this is not an NSA level stuff, just your basic commercial traffic analyzing. And in fact, the most common spying ISPs do is not on DNS or HTTP, but just on IP sessions, i.e. netflow data, they record and store it for months or years. This is likely the first thing you need to protect yourself from.

DoH not just doesn't help privacy, it makes it worse for everyone by letting another party to get their DNS data and by centralizing requests on that party to actually help NSA and large scale commercial spying. ISPs are still going to get that data too though. And theoretical possibility of encrypted SNI is definitely not going to prevent that, it's probably not going to be a thing at all, just remember how quickly all the megacorps jumped in to close the equivalent domain fronting technique under a little bit of pressure from governments forcing megacorps to allow governments to identify traffic to censor something specific or get all their networks blacklisted on the IP level.

Megacorp proposed "security" and "privacy" solutions generally do not do anything good for end users at all only take away control from end users. These are the times we live in.

Post reply on HN