From: cat_mucius
Good day,

Currently if DreamWidth receives request for some journal in form or, it automatically redirects browser to URL. It looks more pretty, but it allows potential inspectors of traffic between clients and DW to see, which specific journal was reached (by DNS query, as well as by plaintext SNI field in SSL handshake) - and block the request.

But if the URLs were remaining with only in the hostname field, then any inspection system would just see that DW was accessed - without knowing any specifics.

Today, many people migrate from LiveJournal to DW because of fear their journals would be blocked by Russian government (which actually happened). It would be nice if DW gave users tools to exclude possibility of such journal-level blocking by government agencies.

What I suggest is: if original request was for URL, let it stay. But if it was for URL or similar - don't redirect the client to "vanity URL", let it stay in this form.

And, of course, redirecting users from HTTP to HTTPS would be great.
jennifer - Answer
Answer (#91889)
Posted: Tue, 27 Dec 2016 04:24:13 GMT

Hi cat_mucius,

I understand and respect your privacy concerns - however, our site setup has long required that we use a separate subdomain for each journal, and this is unlikely to change in the future. If you wish to disguise your browsing habits, the best solution I know of is to use a VPN to fully encrypt your traffic.

As for redirecting HTTP to HTTPS, we do plan to make that happen at some point. For now, if you visit the site using HTTPS, all the browser links should update to use HTTPS as well.

Please let us know if you have any other questions or concerns.


cat_mucius - Comment
Comment (#91906)
Posted: Tue, 27 Dec 2016 08:39:12 GMT

Hi Jennifer, thanks for quick response.

Yes, I see myself that my proposed measure, to be useful, requires modification of all links inside HTML pages, mails, etc. - which is just too much work to prevent possibility of blocking and contradicts other requirements.

Thanks for your time, please feel free to mark this ticket as closed.

>> As for redirecting HTTP to HTTPS, we do plan to make that happen at some point.
Looking ahead. :-)

