• Dessalines
    link
    fedilink
    03 years ago

    Its a man in the middle that recieves every communication to any server that uses it, including ip addresses, signups, passwords, usernames, all in clear text for them. Since so many servers use it, its a giant aggregator as dangerous as a centralized password store.

    • CarrotsHaveEars
      link
      fedilink
      13 years ago

      Just wanna add that it’s impossible for them to have your encrypted messages if you use an HTTPS certificate from another CA.

      • @AgreeableLandscape@lemmy.ml
        link
        fedilink
        0
        edit-2
        3 years ago

        Meta analysis of encrypted traffic is more powerful than you think. By analyzing things like the length and timing of requests and responses, researchers have been able to determine what search term a user typed, what images and videos are being viewed, which threads on a forum they accessed, among other things, without ever decrypting the HTTPS data.