Live data from Hacker News

Spying on HTTPS

textslashplain.com

41–50 of 121 posts

Re: Spying on HTTPS

#41
post #15

> monster in the middle (MITM) That’s not what it stands for. There’s nothing sexist about using an acronym the same way everyone else does.

I have seen it in at least one other project: https://blog.cloudflare.com/monsters-in-the-middleboxes/ , https://github.com/cloudflare/mitmengine I think it's equally understandable, and monster is objectively a more fun word. Seems like not a big deal?

Are we also going to change the middleman to middlemonster?

Re: Spying on HTTPS

#42
post #3

I said awhile back that QUIC leaving out having a "non-s" mode was going to mean people would just leave keys dumping on :(

Which is the desired result, right? Key escrow forces you to be explicit about who you're allowing to decrypt your traffic rather than letting it be everyone by default.

Re: Spying on HTTPS

#43
post #15

> monster in the middle (MITM) That’s not what it stands for. There’s nothing sexist about using an acronym the same way everyone else does.

I thought it was funny. I didn't see it as trying to remove gender as much as talk about how rubbish the practice is (antivirus programs are huge attack vectors, and I assumed the author was calling the anti-virus a Monster).

Chill out. If you start to find offense in everything. you're not going to have a happy life.

Re: Spying on HTTPS

#44
post #5

Earlier quoted context omitted.

I assume you've never heard of ISPs or vendors that _inject_ ads and other shenanigans on non-https and decrypted https websites?

That's the ISP's problem. Mine doesn't do that. I trust it more than Google, at any rate.

You should absolutely not trust an ISP more than Google. Google monetizes your data themselves, while ISPs will pass it around to anyone with a couple bucks...

If data privacy is your goal, keeping both at arms length would be ideal... except most people can't choose how much data* ISPs scoop up, or even choose to switch to a competitor if they disagree with an ISP's policies.

*In contrast, you can control a decent amount of what Google collects on you.

Re: Spying on HTTPS

#45

Earlier quoted context omitted.

I have seen it in at least one other project: https://blog.cloudflare.com/monsters-in-the-middleboxes/ , https://github.com/cloudflare/mitmengine I think it's equally understandable, and monster is objectively a more fun word. Seems like not a big deal?

Are we also going to change the middleman to middlemonster?

No, that would usually be intermediary. If you want to be more specific you can say reseller or broker.

Monster in the middle is at least cute and conveys the authors intent that this agent is untrusted and assumed malicious.

People in this thread clearly don't like being called a monster which I think demonstrates exactly that words matter and these ones are doing their job.

Re: Spying on HTTPS

#46
post #28

Earlier quoted context omitted.

I have seen it in at least one other project: https://blog.cloudflare.com/monsters-in-the-middleboxes/ , https://github.com/cloudflare/mitmengine I think it's equally understandable, and monster is objectively a more fun word. Seems like not a big deal?

It shifts the narrative to demonize MITM. Ironic seeing a Cloudflare link, given that they are MITMing all traffic. You are not a monster if you are doing it, it's corporations who are monsters if they try to prevent you from doing it and you are fighting for freedom from them. So it's freedom-in-the-middle.

SSL termination isn't the same as MITM and you know that.

Re: Spying on HTTPS

#47
post #9

Earlier quoted context omitted.

Being able to choose your ISP is a luxury many people, especially in the US, do not have. Elsewhere there might be choice, but none are really trustworthy. This is about disincentivising ISPs. If it's hard for them to pull off, they wouldn't do it and it would become something normal every ISP does.

This is the thing US brought to itself. Liberal market with minimum regulations. If in my country ISP would touch the traffic, they would get prosecuted by the state. Selling browsing history? Under wiretapping act (you can imagine some jail time). And I can choose between 3 ISPs in country with 2 million people. And optics with at least 100/100 is normal in "larger" city (village in US terms :D) for $60 including ip…

In what country do you live?

Re: Spying on HTTPS

#48
post #40

Earlier quoted context omitted.

How do I choose not to use Google properties, including their ad services, analytics, captcha, maps, etc? Is there at least a comprehensive list of their domains, if I choose to block it all (despite that rendering half the web unusable)?

Host list that lists every one of their domains with ip 0.0.0.0

including every single 1e100 server domain? good luck

Re: Spying on HTTPS

#49

Earlier quoted context omitted.

I have seen it in at least one other project: https://blog.cloudflare.com/monsters-in-the-middleboxes/ , https://github.com/cloudflare/mitmengine I think it's equally understandable, and monster is objectively a more fun word. Seems like not a big deal?

Are we also going to change the middleman to middlemonster?

If you're talking about a security attack or some other "monstrous" situation, and you're communicating your ideas clearly, then sure, who cares

Re: Spying on HTTPS

#50
post #42
post #3

I said awhile back that QUIC leaving out having a "non-s" mode was going to mean people would just leave keys dumping on :(

Which is the desired result, right? Key escrow forces you to be explicit about who you're allowing to decrypt your traffic rather than letting it be everyone by default.

The average user doesn't think like that. They see, "oh in order to get to the next level of farmville I just have to modify this really easy shortcut!"
Post reply on HN