Anyone from governmental agencies who read this article at home or work can now fairly easily be targeted by the relevant surveillance agencies.
Anyone from governmental agencies who read this article at home or work can now fairly easily be targeted by the relevant surveillance agencies.
Edit: Nevermind — I assume you're referring to this scenario[1], in which the company installs a root certificate onto your actual computer that allows them to sign certificates for other sites.
From there, everything can be tracked.
Most government employees are not even in a position to access leakable data even they wanted to. Targeting them based on reading an article would be a waste of effort.
It's less common for companies to have content inspection.
If you mean "transferring over the network", then yes, HTTPS only shows the server you are connecting to, but not the specific URL.
Then again, that can be deduced from the transfer sizes that are still shown.
HTTPS encrypts the URL as well as the content of the communication. Someone surveilling the conversation with the ability to observe all network traffic but without the ability to decrypt SSL traffic would be able to tell that the end user had viewed something at a particular website (technically, at a particular server), but would NOT be able to tell WHICH article was viewed.
That's the new key point for 2017 pro-privacy architectures.
Proof of work surveillance doesn't scale because requiring it leverages the disparity between the total level of Internet traffic and intelligence agency resources.
Kill the dragnets as step 1, then worry about step 2.
Edit: What Mike is trying to implement is based on https://arxiv.org/pdf/1512.00524.pdf.
What about inspecting traffic pattern? I suspect that each article has different size.
Potentially, if they're using TLS/SSL with SNI.
but that's my point... if you're not using SNI, there's only one SSL server on that IP address, and if reverse-DNS fails you, you can connect on port 443 and ask it for its certificate and it will give it to you...
It still might be a better choice, given that the main domain for many sites goes through CDNs and more complex systems in general, increasing the risk of compromise there (which also would expose network details about the submitter, and possibly even more)? A dedicated securedrop site hopefully has dedicated infrastructure and better security.
You got it right the first time around, the parenthetical correction is wrong. The SNI is transmitted in plain text during the TLS handshake.
https encrypts the contents... not things like source/destination often only a destination IP address is required to get URL categories for many Proxy/URL filtering technologies.
securedrop.ap.org
That still gives away a lot, many of these secure drop sites are on a subdomain.
So a surveillance agency could e.g. replace the URLs for the various organizations' leaks landing pages and Tor addresses with phishing pages, and anyone who used them would upload documents directly to the agency.