Re: NNTPS?

Mykola Nikishov <[email protected]>
Newsgroups gmane.discuss
Message-ID <87tvgym8wa.fsf@think>
Robert Pluim <[email protected]> writes:

>> Interesting... Excuse my ignorance, but what
>> would be the benefit of that?
>
> It means that it would require considerably more effort to read our
> discussions on gmane, in theory. Except that they all end up on
> open-access public archives anyway.

Yes, the final message is public and this is expected.

What is not expected that anyone between user's machine and gmane.org is
able to gather information about what exactly and when you're interested
in.

EFF has nice infographic [1] on this matter:

    Click the "HTTPS" button to see what data is visible to
    eavesdroppers when you're using HTTPS.

This is about passive monitoring. Another part of the story is active
monitoring, when anyone between user's machine and gmane.org is able to
modify content on the fly. With STARTTLS, this active actor may fool
user's MUA that server does not support TLS [2].

Someone may argue it is much less likely to happen but anyway, this is
n-1 problems to care about.

[1] https://www.eff.org/pages/tor-and-https
[2] https://www.starttls-everywhere.org/faq/, Downgrade attacks

-- 
Mykola

Libre/Free Java Software Engineer
https://manandbytes.gitlab.io/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.