Live data from Hacker News

Encrypted web traffic now exceeds 90%

netmarketshare.com

251–260 of 311 posts

Re: Encrypted web traffic now exceeds 90%

#251

Earlier quoted context omitted.

Ironically, Telegram markets itself as the most private and secure messenger, but in reality, it's much less private than WhatsApp or Viber: any regular (non-secret) Telegram chats are not end-to-end encrypted - if they were, you wouldn't be able to access them from a new device after authorization with a password.

Accessing chats from a new device has no technical relation (or constraint) to the lack of end to end encryption. Wire encrypts all chats end to end, and still provides syncing conversations to multiple devices on multiple operating systems. It does limit the sync to the last 30 days, but that’s mostly because of cost reasons rather than technical reasons. Edit/correction: Neither Wire nor Signal sync conversations t…

Signal also features multi-device end-to-end encryption.

This non-technical argument feels more and more a shill talking point because the claimed constraint is NEVER provided with technical arguments.

However, it feels intuitive to non-techies: "End-to-end means only one end and I have many devices therefore I have many ends so I can't end-to-end with every end, so better not end-to-end..."

Re: Encrypted web traffic now exceeds 90%

#252

Earlier quoted context omitted.

Telegram is not at all secure, the only real secure product is Signal, which is what Snowden actually recommended.

I continue harping on this point often. The usability, reliability and feature set of Signal are far behind Telegram or WhatsApp. If you want a platform that sometimes works, may be slow in delivering messages, may send false “device changed” notifications, and doesn’t allow a way to backup and restore chats (on iOS), then Signal is the one. If you don’t like any of these deficiencies, then Signal is the last thing t…

Matrix is not usable as it is:

1. Bikeshedding has lead to reduction in security agility: Any change will have to be first implemented for the protocol, then to SDKs, then to clients. This progress can take years.

2. Riot is the only client that delivers proper E2EE, majority of clients don't feature it.

3. E2EE is still not enabled by default.

4. IRC-bridges will break E2EE

5. Decentralization does break large silos and make less tempting targets, but now you have a bunch of server admins who have personal relationships with the people the content (when not end-to-end encrypted), and the metadata (always) of which they have access to.

6. Riot's key management and fingerprint verification has been a nightmare. Thankfully this is about to change.

Until all of these are are fixed, i.e.

Until all clients enforce E2EE, until the protocol design is safe enough, until client vendors are required to keep up with security, until no bridges are allowed, until fingerprints are trivial to compare, I will not, and I think no one should Matrix.

Re: Encrypted web traffic now exceeds 90%

#253
post #113

This statement would be more meaningful had it been phrased something like this: "encrypted web traffic, which most adversaries cannot snoop on, exceeds 90%". There will always be an adversary, far powerful than you, with an ability to snoop on your traffic - be it your ISP, the other endpoint, or owners of the infrastructure that you consume, but do not control.

You portray encryption as a magical energy. To the best understanding of cryptanalysis research, current TLS is secure. Hypothetically it could be broken and publicly unknown, but this is not a matter of "power". > the other endpoint It's not sensible to say encrypted web traffic is snooped on by an actor with direct access to the plaintext.

Moxie has good points about the problems TLS has. And they are not about breaking TLS via cryptanalysis: https://www.youtube.com/watch?v=UawS3_iuHoA

Re: Encrypted web traffic now exceeds 90%

#254
post #73

We often hear the complaint here that nobody cares / cared about Snowden's revelations. But to me it seems he did provide a lot of the impetus for having HTTPS virtually everywhere and a lot of the instant messenging apps being end-to-end encrypted. Most of WhatsApp's users are as non-technical as it gets, and yet they use the kind of encryption that only computer enthusiasts were interested in just a couple years ag…

Snowden was a factor, but not the only one: - CPUs didn't have hardware acceleration for encryption (AES-NI) like they have today, so activating SSL on your webserver actually decreased your throughput a lot - It was expensive and complicated to get a certificate for your website, now LetsEncrypt provides them freely and easily

My P4 could do >400gbps AES128 in 2003. (We tested encrypted connections over Firewire.)

Re: Encrypted web traffic now exceeds 90%

#257
post #83

Earlier quoted context omitted.

What are you talking about about? I think you better look up how https/tls works??? Sure you have to trust the certificate authority. Also can you imagine the scandal that would erupt if Google or AWS cloud was discovered to be eavesdropping on companies running things in their cloud? I don't think so.

> can you imagine the scandal that would erupt if Google or AWS cloud was discovered to be eavesdropping on companies running things in their cloud Remember the "SSL added and removed here" image? https://thumbs.mic.com/MTBjNTQzNTMzZiMvbWVtejZOdjJsaUdUVkZEa...

I am pretty sure that this is a reference to cloudflare.

Re: Encrypted web traffic now exceeds 90%

#258

Earlier quoted context omitted.

Ironically, Telegram markets itself as the most private and secure messenger, but in reality, it's much less private than WhatsApp or Viber: any regular (non-secret) Telegram chats are not end-to-end encrypted - if they were, you wouldn't be able to access them from a new device after authorization with a password.

Accessing chats from a new device has no technical relation (or constraint) to the lack of end to end encryption. Wire encrypts all chats end to end, and still provides syncing conversations to multiple devices on multiple operating systems. It does limit the sync to the last 30 days, but that’s mostly because of cost reasons rather than technical reasons. Edit/correction: Neither Wire nor Signal sync conversations t…

Is it syncing through a centralized server or are they synced between devices?

Re: Encrypted web traffic now exceeds 90%

#259
post #115

Earlier quoted context omitted.

Right. Encrypted web traffic at 90% is different than encrypted web sites at 90%.

When netflix is half, torrent traffic included add in google/facebook/faangs and you arrive at 90% easily.

I thought torrent traffic was generally not encrypted.

Re: Encrypted web traffic now exceeds 90%

#260
post #228

Earlier quoted context omitted.

How is iMessage worse versus Hangouts? Is Hangouts even end-to-end encrypted? IIRC it isn’t, neither is Google Chat (a product which is replacing Hangouts from what I can tell), just Allo and Duo.

That’s not what they said; they’ve said that iMessage has better security than Hangouts, and that this user wouldn’t use anything “worse” ie. further down on their list than iMessage

Sorry about that, you’re correct — I was missing the context of the parent-parent that was referred to.
Post reply on HN