• 0 Posts
  • 42 Comments
Joined 2 years ago
cake
Cake day: December 28th, 2023

help-circle

  • So if they were going to do an attack like this, they wouldn’t do anything like the DH attack you’re talking about, they’d have a custom CA in the browser’s SSL root store. That root cert means they can generate a certificate for any website you visit, and that custom root cert would be how they decrypt your traffic.

    Afaik there isn’t a current attack on proper DH key pairings, but you can’t block the custom certificate path at the browser level without some serious server side work/client side JS to validate

















  • am curious what exactly makes it fall short?

    The podcast playback is sorely lacking. It can’t play more than one episode without having to select the episode, which makes playlists kinda pointless unless it’s just following one storyline in a podcast that runs more than one concurrently. It also doesn’t seem to support defaulting listing order other than newest, and the next episode is always the latest, despite the current playback order



  • Completely agreed, but our opinions don’t change reality, and we see the same sort of requests from countries across the world. If something like this is going to happen, it’s better to fight for the version you want instead of holding your ground in absolute terms and getting whatever is given to you.

    I’d much rather this didn’t exist at all, but if they’re going to do it anyway, this way is much less invasive and could be a lot better for our privacy.

    Even taking this past the parental control aspect, there are plenty of sites that are mandated to age gated, and having that built in and able to dismiss those with a binary of ‘of age’/‘underage’ (confirm to send, obviously) would be great, and would remove the need for some of the existing privacy nightmare ID validation sites. Which would be a overall benefit.