| ▲ | perching_aix an hour ago | |
Was there any TLS interception in place? Mind you, that can be detected and ignored... Cause the (obviously AI generated) page is fairly ambiguous in this regard. In one section it claims certain pieces of info were sent outright. In others, it refers to them as "Privacy Threat Vector" items. Were they possibly sent or were they actually sent? Why is this left unclear? Why is transmission alone counted as evidence of later misuse? What data is technically necessary to send as part of a protocol? I'm really quite tired of the run of the mill "privacy minded" folks thinking they're the hot shit because they can launch WireShark, and gawk at packets flying about. Like no, various corporate SNIs appearing in a chatty network log is not evidence for illegal or unethical corporate espionage/surveillance, especially not a clear one. Nor is the network log being chatty any evidence one way or another. Do you really think that surveillence is a more likely explanation for them than just regular enterprise sprawl? If you're bringing receipts, bring them whole, disclaimers and limitations included. Any analysis that stops before decrypting the traffic is deeply unserious, and only serves to discredit actual research findings & real violations of privacy. | ||