Live data from Hacker News

Encrypted web traffic now exceeds 90%

netmarketshare.com

161–170 of 311 posts

Re: Encrypted web traffic now exceeds 90%

#161

The Federal Government may not like this but this is heading to as it should be. Sometimes the government needs to be saved from itself!

Governments can force CAs to give them certs. HTTPS only stops non-government attackers.

CAs don't have the private keys to the certificates they sign, so this doesn't compromise issued certs.

The ability for CAs to issue extra certs to governments to enable MITM has been reduced a lot by CAA and HPKP.

Re: Encrypted web traffic now exceeds 90%

#162
post #73

We often hear the complaint here that nobody cares / cared about Snowden's revelations. But to me it seems he did provide a lot of the impetus for having HTTPS virtually everywhere and a lot of the instant messenging apps being end-to-end encrypted. Most of WhatsApp's users are as non-technical as it gets, and yet they use the kind of encryption that only computer enthusiasts were interested in just a couple years ag…

Ironically, Telegram markets itself as the most private and secure messenger, but in reality, it's much less private than WhatsApp or Viber: any regular (non-secret) Telegram chats are not end-to-end encrypted - if they were, you wouldn't be able to access them from a new device after authorization with a password.

They don’t claim end to end encryption by default though. You make it sound as if there is a revelation you made here.

Telegram has faults, I would even argue it has many, but it’s clear that only “secret” chats and voice/video calls are end to end encrypted.

Whatsapp, however, does allow you to download all of your messages from your device using WhatsApp web, and they were recently shown to have an exploit/backdoor in the applications themselves. So in that context they’re comparable in my opinion.

Re: Encrypted web traffic now exceeds 90%

#163
post #73

We often hear the complaint here that nobody cares / cared about Snowden's revelations. But to me it seems he did provide a lot of the impetus for having HTTPS virtually everywhere and a lot of the instant messenging apps being end-to-end encrypted. Most of WhatsApp's users are as non-technical as it gets, and yet they use the kind of encryption that only computer enthusiasts were interested in just a couple years ag…

He was very useful to inform the wider audience about global surveillance, make it "we already know that - boring!" and accelerate the progress of laws to extend it. In the end, this was his mission. edit: thank you for the downvote, well-informed stranger!

19 days before Snowden flew to Hong Kong, former FBI counter-terrorism agent Tim Clemente spilled the beans on CNN[0] (for context, informarion from a phonecall between one of the Boston Marathon bombers and his wife had been leaked to the media):

>BURNETT: Tim, is there any way, obviously, there is a voice mail they can try to get the phone companies to give that up at this point. It's not a voice mail. It's just a conversation. There's no way they actually can find out what happened, right, unless she tells them?

>CLEMENTE: No, there is a way. We certainly have ways in national security investigations to find out exactly what was said in that conversation. It's not necessarily something that the FBI is going to want to present in court, but it may help lead the investigation and/or lead to questioning of her. We certainly can find that out.

>BURNETT: So they can actually get that? People are saying, look, that is incredible.

>CLEMENTE: No, welcome to America. All of that stuff is being captured as we speak whether we know it or like it or not.

This could be coincidental timing, but I've always wondered if the Snowden leak was a way of controlling the national discussion around the issue and putting an agent in place (Snowden) who could be a relatively moderate voice that the pro-privacy crowd could group around, while also creating a dramatic story with the potential for international espionage that allows pro-surveillance voices to distract from the they're-spying-on-us narrative by accusing Snowden of being a Chinese/Russian pawn. I don't feel comfortable saying Snowden is still working for the US government, but I'm certainly suspicious of him.

[0]: http://transcripts.cnn.com/TRANSCRIPTS/1305/01/ebo.01.html

Re: Encrypted web traffic now exceeds 90%

#165
post #73

We often hear the complaint here that nobody cares / cared about Snowden's revelations. But to me it seems he did provide a lot of the impetus for having HTTPS virtually everywhere and a lot of the instant messenging apps being end-to-end encrypted. Most of WhatsApp's users are as non-technical as it gets, and yet they use the kind of encryption that only computer enthusiasts were interested in just a couple years ag…

If people really listened to Snowden they wouldn't be relying on CA authorities for certificates.

There have been fradulent certificates in the wild in the past but the CAs doing it usually get kicked out pretty quickly. That's what Google's certificate transparency project is for. And they are increasing requirements further and further. Hopefully one day we'll get to a state where the infrastructure of multiple independent companies in different countries needs to be compromised in order for one successful forgery. But even now certificate transparency has greatly reduced the number of entities able to forge certificates.

Re: Encrypted web traffic now exceeds 90%

#166

Earlier quoted context omitted.

> from mobile apps (most of which have to be encrypted now I think) Since the end of 2016 on iOS and since Android v9, apps have to communicate over HTTPS. I guess you can technically visit HTTP sites via a browser, but I'd bet that >90% of the traffic from smartphones is over HTTPS.

> since Android v9, apps have to communicate over HTTPS That isn't true. It is the default but Android lets you override the defaults and use unencrypted traffic both in WebViews and in networking APIs.

It’s not true in iOS either. It’s possible for an app to whitelist specific domains.

Re: Encrypted web traffic now exceeds 90%

#167
post #73

We often hear the complaint here that nobody cares / cared about Snowden's revelations. But to me it seems he did provide a lot of the impetus for having HTTPS virtually everywhere and a lot of the instant messenging apps being end-to-end encrypted. Most of WhatsApp's users are as non-technical as it gets, and yet they use the kind of encryption that only computer enthusiasts were interested in just a couple years ag…

Ironically, Telegram markets itself as the most private and secure messenger, but in reality, it's much less private than WhatsApp or Viber: any regular (non-secret) Telegram chats are not end-to-end encrypted - if they were, you wouldn't be able to access them from a new device after authorization with a password.

Telegram is not at all secure, the only real secure product is Signal, which is what Snowden actually recommended.

Re: Encrypted web traffic now exceeds 90%

#168
post #154

Earlier quoted context omitted.

Ironically, Telegram markets itself as the most private and secure messenger, but in reality, it's much less private than WhatsApp or Viber: any regular (non-secret) Telegram chats are not end-to-end encrypted - if they were, you wouldn't be able to access them from a new device after authorization with a password.

they are not end-to-end encrypted but they are encrypted. Also, I read that WhatsApp is going to switch to the same mode, for user convenience: https://bgr.com/2019/07/29/whatsapp-update-to-bring-multi-pl...

Oh, come on! If Telegram can decrypt chats for a user, they can decrypt it if they really want. Any other kind of encryption is irrelevant - from third party attackers, tls works good enough.

Re: Encrypted web traffic now exceeds 90%

#169

Earlier quoted context omitted.

Ironically, Telegram markets itself as the most private and secure messenger, but in reality, it's much less private than WhatsApp or Viber: any regular (non-secret) Telegram chats are not end-to-end encrypted - if they were, you wouldn't be able to access them from a new device after authorization with a password.

To add to the irony: Telegram has evolved in a bit of a darknet on its own where people casual share content that would be near impossible to find on the surface web.

how do I get in on this?

Re: Encrypted web traffic now exceeds 90%

#170

Earlier quoted context omitted.

He was very useful to inform the wider audience about global surveillance, make it "we already know that - boring!" and accelerate the progress of laws to extend it. In the end, this was his mission. edit: thank you for the downvote, well-informed stranger!

19 days before Snowden flew to Hong Kong, former FBI counter-terrorism agent Tim Clemente spilled the beans on CNN[0] (for context, informarion from a phonecall between one of the Boston Marathon bombers and his wife had been leaked to the media): >BURNETT: Tim, is there any way, obviously, there is a voice mail they can try to get the phone companies to give that up at this point. It's not a voice mail. It's just a…

Snowden released a large collection of documents. Judging by his interview with Joe Rogan, he's a passionate advocate for encryption and says that the US is creating a tool for complete oppression. It's harder to get more apocalyptic than that.
Post reply on HN