• [^] # Re: HTTPS Everywhere

    Posté par (site web personnel) . En réponse à la dépêche Protéger sa vie privée sur le Web, exemple avec Firefox. Évalué à 2.

    La FAQ de l'extension dont j'ai donné le lien dans la dépêche et qui énonce :

    However, HTTPS Everywhere does not conceal the identities of the sites you access, the amount of time you spend using them, or the amount of information you upload or download from a particular site. For example, if you access http://www.eff.org/issues/nsa-spying and HTTPS Everywhere rewrites it to https://www.eff.org/issues/nsa-spying, an eavesdropper can still trivially recognize that you are accessing www.eff.org (but might not know which issue you are reading about). In general, the entire hostname part of the URL remains exposed to the eavesdropper because this must be sent repeatedly in unencrypted form while setting up the connection. Another way of saying this is that HTTPS was never designed to conceal the identity of the sites that you visit.

    Ce qui est contraire à ce qu'énonce Goffi.

    Donc deux assertions qui se contredisent, et moi au milieu qui ne suis pas expert je ne sais qu'en penser si ce n'est que le paragraphe de l'EFF semble précis à ce sujet ?