Hacker News new | past | comments | ask | show | jobs | submit | throwaway54235's comments login

No! Solving the SNI problem is far from enough.

The server IP address can be easily correlated with the domain for 90% of Internet traffic.


Do you have a citation for only 10% of internet traffic using CDNs? Even things like cloud load-balances and ephemeral IPs make those associations hard and we’re in third decade of major web properties using CDNs.


The only solution is onion routing AKA Tor and similar.


REMINDER: Research proves that it's easy to correlate IP addresses in HTTP[S] connections with the domain you are connecting to with a very high success rate.

You can resolve the websites from the Alexa top 100k list and create a ipaddr -> website map that will successfully apply to 90% of Internet traffic without ambiguity.

A lot of research papers also show how easy it is to fingerprint and detect a TLS handshake.

Assuming the SNI problem is going to be solved, the other problems are still here.

TL;DR: use Tor.


I worked on one of the large commercial projects that offers OS-packaged k8s.

The customers were screaming for it. They want a simpla and reliable way to deploy k8s without a team of specialist, and the guarantee to receive security updates for years without having to upgrade to a new version.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: