• mint_tamasEnglish
    arrow-up
    10
    arrow-down
    1
    ·
    10 days ago
    link
    fedilink

    With TLS and DoH, how is your bank and other information leaked?

    • obviouspornaltEnglish
      arrow-up
      11
      arrow-down
      0
      ·
      10 days ago
      link
      fedilink

      He said “which bank”, which could be determined by the sniffing DNS requests, or seeing which IPs his computer is connecting to.

      Not a breach of his personal information (assuming the bank that he’s using and the client he’s using after putting everything in TLS properly).

      • mint_tamasEnglish
        arrow-up
        2
        arrow-down
        2
        ·
        10 days ago
        link
        fedilink

        But with DoH you can’t sniff the DNS, that’s the whole point.

        • r00ty
          arrow-up
          7
          arrow-down
          0
          ·
          10 days ago
          link
          fedilink

          But you can see the ip address, which will id the bank. They can derive other information by ip addresses or leaked data and there’s still things using unencrypted connections even today. I generally just connect to my home vpn so at least it’s inly my isp spying on me.

          • ludEnglish
            arrow-up
            2
            arrow-down
            0
            ·
            10 days ago
            link
            fedilink

            Generally you can also read the SNI.

            • r00ty
              arrow-up
              1
              arrow-down
              0
              ·
              10 days ago
              link
              fedilink

              I think this is one of the things that ech is meant to solve. But ech/esni is still not widespread on smaller sites yet I think.

        • phillippEnglish
          arrow-up
          1
          arrow-down
          0
          ·
          9 days ago
          link
          fedilink

          You actually still can. Have a look at DNS fingerprinting

    • OneMeaningManyNamesEnglish
      arrow-up
      10
      arrow-down
      0
      ·
      10 days ago
      link
      fedilink

      Possibly the domain is visible with a traffic monitoring tool. Everything else is between you and the bank via HTTPS. Having said that, whatever is not over https is visible to whoever sits on the same network as yourself.

      • blarthEnglish
        arrow-up
        6
        arrow-down
        0
        ·
        10 days ago
        link
        fedilink

        Importantly, you probably don’t know what all is encrypted in every app you use on your phone, so it’s best practice to encrypt the transport.