Hacker News new | ask | show | jobs
by sph 1149 days ago
The only way NSA can record the URL without having infiltrated Kagi's datacenter, is for them to have broken the encryption algorithms behind TLS/HTTPS.

If that's the case, nowhere on the regular Internet is safe.

Snowden revealed that NSA has infiltrated all the major industry players (Apple, Microsoft, Google, etc.), also ISPs. But the only way NSA can know what your plaintext HTTPS URL is either by having access to your PC, or having access to Kagi's servers. Or as I said, that they've cracked encryption schemes everyone assumes to be safe.

1 comments

> is for them to have broken the encryption algorithms behind TLS/HTTPS.

Or if they have access to, or can subpoena, a MitMaaS for HTTPS. Like Cloudflare.

True. Given how widespread Cloudflare has become, I would be surprised if they haven't got a tap there already.