Re: NNTPS?
Robert Pluim <[email protected]>
| Newsgroups | gmane.discuss |
|---|---|
| Message-ID | <[email protected]> |
Mykola Nikishov <[email protected]> writes: > Robert Pluim <[email protected]> writes: > >>> Interesting... Excuse my ignorance, but what >>> would be the benefit of that? >> >> It means that it would require considerably more effort to read our >> discussions on gmane, in theory. Except that they all end up on >> open-access public archives anyway. > > Yes, the final message is public and this is expected. > > What is not expected that anyone between user's machine and gmane.org is > able to gather information about what exactly and when you're interested > in. Not something Iʼm too worried about in the context of gmane, but there are people for which that is not true. > EFF has nice infographic [1] on this matter: > > Click the "HTTPS" button to see what data is visible to > eavesdroppers when you're using HTTPS. > > This is about passive monitoring. Another part of the story is active > monitoring, when anyone between user's machine and gmane.org is able to > modify content on the fly. With STARTTLS, this active actor may fool > user's MUA that server does not support TLS [2]. Yes, which is why the IETF is trying to get rid of STARTTLS (and good riddance to it). Robert