How much cleartext is sent over the net? Nowadays almost everything is encrypted, even things like DoH are becoming standard via Cloudflare/Apple Private Relay.
If I were a politician using this against an opponent, I'd write the following press release:
Websites in the range 54.239.0.0/8 often host problematic content. My opponent visited several addresses in this range overnight and hid his traffic with military-grade message scrambling functionality.
Of course that's just AWS and you can't even do HTTP/2 or HTTP/3 without encryption. But do the voters know that? Will they be educated on it? Probably not. And you're not saying anything untrue, you have facts and logs to back up your assertions!
I'm not a crypto expert by any means, but it is my understanding that government actors of larger countries probably have trusted CAs in most devices on the planet that they have control over, and they could issue certificates for arbitrary domain names; and your devices would for the most part be none the wiser.
Of course this is only relevant for targeted surveillance, not mass surveillance.
Happy to be corrected though, I've been wondering about this.
Perhaps think a bit smaller, and look at companies that operate office-sized TLS interception by installing a CA certificate on each (managed) end device, and generating certificates on-the-fly from that CA. Then, some middlebox is able to inspect the encrypted communication that passes through.
Some web browsers have pinned certificates for certain services, Google Chrome/Chromium being one of those. Subsequently, the browser refuses to perform any more actions towards the server that serves an invalid (according to the browser) certificate. That browser is also one of the reasons the DigiNotar case in 2011 emerged to the surface.
Perhaps a better insight is looking at parties doing TLS termination globally as a reverse proxy service, for example for DDoS mitigation or acting as a web application firewall. Or, who handles your (encrypted) DNS requests? A somewhat trustworthy local ISP, or a large corporation with multiple pages of terms of service and a vague privacy statement? (I'm unfortunately also aware that there exist ISPs that inject ads on non-encrypted connections, or having done so in the past)
In my opinion, it's less about the amount of cleartext traffic, but also about what parties terminate your so preciously encrypted connections/requests, the percentage of internet traffic they handle, and what they exactly store about those requests.
Encryption on the internet doesn't mean it's suddenly safe.
Metadata analysis on netflow, source and destination traffic, etc.
Most people still don't use VPNs for everything, and some services outright block or degrade VPN connectivity. Two notable examples are most banks, and 4chan.
The majority of traffic is available as cleartext to Cloudflare so that they can analyse it. That’s the point of being an enormous centralised TLS termination proxy.
Comments
How much cleartext is sent over the net? Nowadays almost everything is encrypted, even things like DoH are becoming standard via Cloudflare/Apple Private Relay.
If I were a politician using this against an opponent, I'd write the following press release:
Websites in the range 54.239.0.0/8 often host problematic content. My opponent visited several addresses in this range overnight and hid his traffic with military-grade message scrambling functionality.
Of course that's just AWS and you can't even do HTTP/2 or HTTP/3 without encryption. But do the voters know that? Will they be educated on it? Probably not. And you're not saying anything untrue, you have facts and logs to back up your assertions!
I'm not a crypto expert by any means, but it is my understanding that government actors of larger countries probably have trusted CAs in most devices on the planet that they have control over, and they could issue certificates for arbitrary domain names; and your devices would for the most part be none the wiser.
Of course this is only relevant for targeted surveillance, not mass surveillance.
Happy to be corrected though, I've been wondering about this.
Perhaps think a bit smaller, and look at companies that operate office-sized TLS interception by installing a CA certificate on each (managed) end device, and generating certificates on-the-fly from that CA. Then, some middlebox is able to inspect the encrypted communication that passes through.
Some web browsers have pinned certificates for certain services, Google Chrome/Chromium being one of those. Subsequently, the browser refuses to perform any more actions towards the server that serves an invalid (according to the browser) certificate. That browser is also one of the reasons the DigiNotar case in 2011 emerged to the surface.
This is precisely the threat model that certificate transparency mitigates.
Perhaps a better insight is looking at parties doing TLS termination globally as a reverse proxy service, for example for DDoS mitigation or acting as a web application firewall. Or, who handles your (encrypted) DNS requests? A somewhat trustworthy local ISP, or a large corporation with multiple pages of terms of service and a vague privacy statement? (I'm unfortunately also aware that there exist ISPs that inject ads on non-encrypted connections, or having done so in the past)
In my opinion, it's less about the amount of cleartext traffic, but also about what parties terminate your so preciously encrypted connections/requests, the percentage of internet traffic they handle, and what they exactly store about those requests.
Encryption on the internet doesn't mean it's suddenly safe.
Store now, decrypt later?
Metadata analysis on netflow, source and destination traffic, etc.
Most people still don't use VPNs for everything, and some services outright block or degrade VPN connectivity. Two notable examples are most banks, and 4chan.
I firmly believe 4ch is a Honeypot.
The majority of traffic is available as cleartext to Cloudflare so that they can analyse it. That’s the point of being an enormous centralised TLS termination proxy.
They all work for the same team