[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Gopher over TLS



On 07/12/2021 16:21, Gene Michael Stover wrote:
Mateusz writes:
 > Integrity does not imply encryption (of the payload).

True, but encryption is one way to detect tampering.

No, it is not. Encryption without authentication is useless. A MITM can easily provide you with encrypted content that he encrypted with his own private key (and that you decipher using the public key you obtained from his fake x509 certificate).

Onion sites provide pseudonymity to their clients (also privacy over the wire), but don't attempt to tie a server with an organization.  Might be more
appropriate for Gopher.

I have the feeling that people simply do not use the proper tool for their needs. There is a ton of P2P networks out there that are far better suited than Gopher when it comes to secretly downloading ascii-arts of nude robot ladies.

Mateusz
--
discuss gopher on the USENET: comp.infosystems.gopher
gopher://gopher.viste.fr/0/whyusenet.txt


Reply to: