Bug#750522: Encrypted repos (https/ftps)

DNS <[email protected]>
Newsgroups gmane.linux.debian.devel.bugs.general,gmane.linux.debian.user.mirrors
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

I wonder a bit, i currently see not the single downloads only the
complete download of all files when using https.
Does this doesn't matter? Or better said: Is it still possible that it
leaks the single file sizes like that?
And if it leaks the file sizes how easy/hard is this to know the actual
file names which have been downloaded?

Regards

On 18.10.2014 22:01, Kurt Roeckx wrote:
> On Fri, Oct 10, 2014 at 09:59:03PM +0200, Axel Beckert wrote:
>> Hi Kurt,
>>
>> Kurt Roeckx wrote:
>>>> The issue is that our ISPs can see the names of the packages that we
>>>> download, and i don't think anybody needs to see that. With encrypted
>>>> connections this issue would be solved.
>>>
>>> Encrypting it will not solve that.  It will only make it slightly
>>> harder.
>>
>> In don't why that should make it only slightly harder. Please explain.
>
> Because it leaks things like the size of all the packages you're
> downloading.  apt doesn't do pipelining.
>
>
> Kurt
>
>

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBAgAGBQJUQ/Z9AAoJEIuhUod3cZQFzXwP/3b/M8A8YVsUm2JcYHb3uDbx
LsUK1DJxP01QFjCvmoI/cnMibZd3AKFh2c65fjxG4b8njKA3+0isjBXKfb2ktB6U
wAMgwJAoQfbkPwyM5Zbmww8q0dy5GqdPiBNzTdn3Bsf8MWKdsQmsxrjHM7B3qnBT
3TxShbZpczeOb4jkyUnGWPnMHImQK5p0A/0x5qo6NoNu+kZvda5Ob3fLq6q9pUq6
dp+Pyce+Lp0g4IBlNLarEvrckSrwVVZGzKVINBwd9B+52eYBOUcW9y7dtUjWXcvu
L2QKaPfsZRqt+cdYJ80ks7aW4MEVBv352SRa9LIMMdOJ/1wpT4Z6W5oJwKep/CBb
usytMyKuZ/211Jx3UZAyBUUl9BmhZr4m9lrxhK1gVTeoO6rzWW7z77ir/aKbumGO
0Xs6JgUCRdKgxxJGAMS82j6EsYYq/k5BXQWn4Yxs+bCaBXedcxsDiqcoaTpYBhX4
HGdHT9lK2y4Kv4lnufZw47iNpjr4LEeYoHdhPrfUPVgnTco+HsWkSBERJf9vCNfV
p+OThbe83FsnOce3O1F8R3yRnFPo1ZO4vXA3X1Cavw9tPokDIR+/lbIsVI2Gn9Zn
eCZdogLRzxPp76yzb2RUtKFAW3ajqjuigrX6j/cs0OVXGPYB4jw0AFRVm/1hjxj4
nGqG/PX0y2Ccf0lSJ7KD
=c8kw
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.