Re: NNTPS?
Mykola Nikishov <[email protected]>
| Newsgroups | gmane.discuss |
|---|---|
| Message-ID | <87tvgym8wa.fsf@think> |
Robert Pluim <[email protected]> writes: >> Interesting... Excuse my ignorance, but what >> would be the benefit of that? > > It means that it would require considerably more effort to read our > discussions on gmane, in theory. Except that they all end up on > open-access public archives anyway. Yes, the final message is public and this is expected. What is not expected that anyone between user's machine and gmane.org is able to gather information about what exactly and when you're interested in. EFF has nice infographic [1] on this matter: Click the "HTTPS" button to see what data is visible to eavesdroppers when you're using HTTPS. This is about passive monitoring. Another part of the story is active monitoring, when anyone between user's machine and gmane.org is able to modify content on the fly. With STARTTLS, this active actor may fool user's MUA that server does not support TLS [2]. Someone may argue it is much less likely to happen but anyway, this is n-1 problems to care about. [1] https://www.eff.org/pages/tor-and-https [2] https://www.starttls-everywhere.org/faq/, Downgrade attacks -- Mykola Libre/Free Java Software Engineer https://manandbytes.gitlab.io/