Re: Gopher over TLS

Mateusz Viste <mateusz-5L880J/[email protected]> Tue, 7 Dec 2021 17:11:40 +0100
Newsgroups gmane.network.gopher.general
Message-ID <[email protected]>
On 07/12/2021 16:21, Gene Michael Stover wrote:
> Mateusz writes:
>  > Integrity does not imply encryption (of the payload).
> 
> True, but encryption is one way to detect tampering.

No, it is not. Encryption without authentication is useless. A MITM can 
easily provide you with encrypted content that he encrypted with his own 
private key (and that you decipher using the public key you obtained 
from his fake x509 certificate).

> Onion sites provide pseudonymity to their clients (also privacy over the 
> wire), but don't attempt to tie a server with an organization.  Might be more
> appropriate for Gopher.

I have the feeling that people simply do not use the proper tool for 
their needs. There is a ton of P2P networks out there that are far 
better suited than Gopher when it comes to secretly downloading 
ascii-arts of nude robot ladies.

Mateusz
-- 
discuss gopher on the USENET: comp.infosystems.gopher
gopher://gopher.viste.fr/0/whyusenet.txt