Hacker News new | past | comments | ask | show | jobs | submit login

The result of this is generalizable. Looking at your encrypted HTTPS traffic, people can still tell what you are browsing and downloading especially when they have a good idea of what you could browse or download.

For the rest, I am not sure how many people should be afraid to let people know what they are watching on Netflix.




Yep, people can infer a lot. I did a demo of this a couple of years ago for my employer at the time by creating a tool which, in a slightly contrived scenario, is able to figure out what one is looking at on Google Maps over SSL.

Blogpost (includes demo vid): http://blog.ioactive.com/2012/02/ssl-traffic-analysis-on-goo...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: