(no title)
NotPractical | 4 months ago
[1] https://www.eff.org/deeplinks/2024/08/federal-appeals-court-...
[2] https://techcrunch.com/2023/12/16/google-geofence-warrants-l...
NotPractical | 4 months ago
[1] https://www.eff.org/deeplinks/2024/08/federal-appeals-court-...
[2] https://techcrunch.com/2023/12/16/google-geofence-warrants-l...
kube-system|4 months ago
vintermann|4 months ago
Sophira|4 months ago
In this case, there's an explicit middle point - chatgpt.com resolves to a CloudFlare server, so CloudFlare is actually one of the ends here. It likely acts as a reverse proxy, meaning that it will forward your requests to a different, OpenAI-owned server. This might be over a new HTTPS connection, or it might be over an unencrypted HTTP connection.
It really is super important to emphasize this point. End-to-end encryption is not simply that your data is encrypted between you and the ultimate endpoint. It's that it can't be decrypted along the way - and decrypting your HTTPS requests is something that CloudFlare needs to do in order to work.
(To be clear, I'm not accusing CloudFlare of anything shady here. I'm just saying that people have forgotten what end-to-end encryption really means.)
addaon|4 months ago