{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:EE6BSQFMZRCJJVXGQBF5NC6VD3","short_pith_number":"pith:EE6BSQFM","canonical_record":{"source":{"id":"1805.11544","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-05-29T15:42:02Z","cross_cats_sorted":[],"title_canon_sha256":"8859e5c2ddab12016b9de857cddcf317170ab5eba2bbaae7fff8733b374e0d88","abstract_canon_sha256":"9ff059db488ff9c498df38f52a2a1947946dcb73569581a3addf68e58c3fa5c2"},"schema_version":"1.0"},"canonical_sha256":"213c1940accc4494d6e6804bd68bd51ef3db6c500143f8132d52174018fdc1ff","source":{"kind":"arxiv","id":"1805.11544","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1805.11544","created_at":"2026-05-18T00:14:42Z"},{"alias_kind":"arxiv_version","alias_value":"1805.11544v1","created_at":"2026-05-18T00:14:42Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1805.11544","created_at":"2026-05-18T00:14:42Z"},{"alias_kind":"pith_short_12","alias_value":"EE6BSQFMZRCJ","created_at":"2026-05-18T12:32:22Z"},{"alias_kind":"pith_short_16","alias_value":"EE6BSQFMZRCJJVXG","created_at":"2026-05-18T12:32:22Z"},{"alias_kind":"pith_short_8","alias_value":"EE6BSQFM","created_at":"2026-05-18T12:32:22Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:EE6BSQFMZRCJJVXGQBF5NC6VD3","target":"record","payload":{"canonical_record":{"source":{"id":"1805.11544","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-05-29T15:42:02Z","cross_cats_sorted":[],"title_canon_sha256":"8859e5c2ddab12016b9de857cddcf317170ab5eba2bbaae7fff8733b374e0d88","abstract_canon_sha256":"9ff059db488ff9c498df38f52a2a1947946dcb73569581a3addf68e58c3fa5c2"},"schema_version":"1.0"},"canonical_sha256":"213c1940accc4494d6e6804bd68bd51ef3db6c500143f8132d52174018fdc1ff","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:14:42.110446Z","signature_b64":"VA2pFAtkFswfyjKGlgZq30cJk8KxplMql3OGtJ5H6b7bKu3zIicBk5dWVHtvDNnQfpHAIZx6gTjxym8vgcxlCw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"213c1940accc4494d6e6804bd68bd51ef3db6c500143f8132d52174018fdc1ff","last_reissued_at":"2026-05-18T00:14:42.109642Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:14:42.109642Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1805.11544","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:14:42Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"LmnXjskbweWvrF84g+rYmLI9Znb7jqTDlU7h1myLr8hBo1xEa55cOLh5NFscZI3p9QL2CLplSmtwhZedUBDxBg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-22T13:03:44.554207Z"},"content_sha256":"07b815d8b9e1419dc00498c19c9e50a6b74110593b1221e4b2b436bfca71f684","schema_version":"1.0","event_id":"sha256:07b815d8b9e1419dc00498c19c9e50a6b74110593b1221e4b2b436bfca71f684"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:EE6BSQFMZRCJJVXGQBF5NC6VD3","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Limitless HTTP in an HTTPS World: Inferring the Semantics of the HTTPS Protocol without Decryption","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Andrew Chi, Blake Anderson, David McGrew, Scott Dunlop","submitted_at":"2018-05-29T15:42:02Z","abstract_excerpt":"We present new analytic techniques for inferring HTTP semantics from passive observations of HTTPS that can infer the value of important fields including the status-code, Content-Type, and Server, and the presence or absence of several additional HTTP header fields, e.g., Cookie and Referer. Our goals are twofold: to better understand the limitations of the confidentiality of HTTPS, and to explore benign uses of traffic analysis such as application troubleshooting and malware detection that could replace HTTPS interception and static private keys in some scenarios. We found that our techniques"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1805.11544","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:14:42Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"C9sWnuy934bcqp0gjAOELl/fD3HYx+vE4YlCWNoe7JTuwxBo5j5ihFug0NcRG+tobmxOI1gFDYPm02TdN4CLBQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-22T13:03:44.554606Z"},"content_sha256":"4210ea04c4e4e83114f64152f4ba51db39a6bd5d8ab69400db9b84fc04e86bba","schema_version":"1.0","event_id":"sha256:4210ea04c4e4e83114f64152f4ba51db39a6bd5d8ab69400db9b84fc04e86bba"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/EE6BSQFMZRCJJVXGQBF5NC6VD3/bundle.json","state_url":"https://pith.science/pith/EE6BSQFMZRCJJVXGQBF5NC6VD3/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/EE6BSQFMZRCJJVXGQBF5NC6VD3/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-22T13:03:44Z","links":{"resolver":"https://pith.science/pith/EE6BSQFMZRCJJVXGQBF5NC6VD3","bundle":"https://pith.science/pith/EE6BSQFMZRCJJVXGQBF5NC6VD3/bundle.json","state":"https://pith.science/pith/EE6BSQFMZRCJJVXGQBF5NC6VD3/state.json","well_known_bundle":"https://pith.science/.well-known/pith/EE6BSQFMZRCJJVXGQBF5NC6VD3/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:EE6BSQFMZRCJJVXGQBF5NC6VD3","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"9ff059db488ff9c498df38f52a2a1947946dcb73569581a3addf68e58c3fa5c2","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-05-29T15:42:02Z","title_canon_sha256":"8859e5c2ddab12016b9de857cddcf317170ab5eba2bbaae7fff8733b374e0d88"},"schema_version":"1.0","source":{"id":"1805.11544","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1805.11544","created_at":"2026-05-18T00:14:42Z"},{"alias_kind":"arxiv_version","alias_value":"1805.11544v1","created_at":"2026-05-18T00:14:42Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1805.11544","created_at":"2026-05-18T00:14:42Z"},{"alias_kind":"pith_short_12","alias_value":"EE6BSQFMZRCJ","created_at":"2026-05-18T12:32:22Z"},{"alias_kind":"pith_short_16","alias_value":"EE6BSQFMZRCJJVXG","created_at":"2026-05-18T12:32:22Z"},{"alias_kind":"pith_short_8","alias_value":"EE6BSQFM","created_at":"2026-05-18T12:32:22Z"}],"graph_snapshots":[{"event_id":"sha256:4210ea04c4e4e83114f64152f4ba51db39a6bd5d8ab69400db9b84fc04e86bba","target":"graph","created_at":"2026-05-18T00:14:42Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"We present new analytic techniques for inferring HTTP semantics from passive observations of HTTPS that can infer the value of important fields including the status-code, Content-Type, and Server, and the presence or absence of several additional HTTP header fields, e.g., Cookie and Referer. Our goals are twofold: to better understand the limitations of the confidentiality of HTTPS, and to explore benign uses of traffic analysis such as application troubleshooting and malware detection that could replace HTTPS interception and static private keys in some scenarios. We found that our techniques","authors_text":"Andrew Chi, Blake Anderson, David McGrew, Scott Dunlop","cross_cats":[],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-05-29T15:42:02Z","title":"Limitless HTTP in an HTTPS World: Inferring the Semantics of the HTTPS Protocol without Decryption"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1805.11544","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:07b815d8b9e1419dc00498c19c9e50a6b74110593b1221e4b2b436bfca71f684","target":"record","created_at":"2026-05-18T00:14:42Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"9ff059db488ff9c498df38f52a2a1947946dcb73569581a3addf68e58c3fa5c2","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-05-29T15:42:02Z","title_canon_sha256":"8859e5c2ddab12016b9de857cddcf317170ab5eba2bbaae7fff8733b374e0d88"},"schema_version":"1.0","source":{"id":"1805.11544","kind":"arxiv","version":1}},"canonical_sha256":"213c1940accc4494d6e6804bd68bd51ef3db6c500143f8132d52174018fdc1ff","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"213c1940accc4494d6e6804bd68bd51ef3db6c500143f8132d52174018fdc1ff","first_computed_at":"2026-05-18T00:14:42.109642Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:14:42.109642Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"VA2pFAtkFswfyjKGlgZq30cJk8KxplMql3OGtJ5H6b7bKu3zIicBk5dWVHtvDNnQfpHAIZx6gTjxym8vgcxlCw==","signature_status":"signed_v1","signed_at":"2026-05-18T00:14:42.110446Z","signed_message":"canonical_sha256_bytes"},"source_id":"1805.11544","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:07b815d8b9e1419dc00498c19c9e50a6b74110593b1221e4b2b436bfca71f684","sha256:4210ea04c4e4e83114f64152f4ba51db39a6bd5d8ab69400db9b84fc04e86bba"],"state_sha256":"b8073ce429da327f9ef6225971f964efb668be67b9215d4a74d5b0ece1e70642"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"0dbgie4tpYu9GDqwNZr5pSs8Ro8SxzwN1mcYriJMOBkZ/QwV9flatNdSEcJ8UL3aTIRpnQeJ6i60IwUZGGd2Bw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-22T13:03:44.556552Z","bundle_sha256":"000d99712d519e4480b93bc0c372227de6730944ae8962292f000bbca3448c62"}}