Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

To be honest, I don't understand how using HTTPS in Google search will help users to browse web more securely. I am not going to use this feature. The bad thing is that lots of non-technical users who care about security and privacy will use it, and they'll get an illusion that their web surfing has become more secure.


It's not an illusion. Your ISP can't see what you're searching for. The coffee shop wifi administrator can't see what you're searching for. Your boss can't find out what you're searching for from your mobile phone over your company's wifi network. The owners of the websites in the SERPs can't see what you searched for, and they can't give that information to anybody else (e.g. Facebook Connect).

(Well, they can all do traffic analysis. But, for Google searches, traffic analysis is too much work for almost any of them to do and the results would be so inconclusive that it's practically useless.)


I don't think ISP cannot see what I'm searching for if Google allows me to use HTTPS. When we use HTTPS, data is encrypted. But URLs I'm querying are still open for anyone. If someone knows that I queried, for example, http://www.google.co.uz/?q=google, it's pretty easy to understand what I've been searching for.


HTTPS doesn't send the URL unencrypted. The intermediary can tell that you access google.com from the DNS records and from the TLS certificate, and it can analyze the lengths and timings of the request and response, but that's it.


I didn't know that. Thank you so much.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: