Live data from Hacker News

Industry Concerns about TLS 1.3

ietf.org

11–20 of 194 posts

Re: Industry Concerns about TLS 1.3

#11
post #6

"Like many enterprises, financial institutions depend upon the ability to decrypt TLS traffic to implement data loss protection, intrusion detection and prevention, malware detection, packet capture and analysis, and DDoS mitigation. Unlike some other businesses, financial institutions also rely upon TLS traffic decryption to implement fraud monitoring and surveillance of supervised employees." I'm at lost here. What…

They key phrase is "rely upon", meaning they went down a route of using a clever hack rather than formally designing a system to meet their goals.

I wonder why SOCKs proxies, which every browser supports, wouldn't work for them.

Re: Industry Concerns about TLS 1.3

#13
post #6

"Like many enterprises, financial institutions depend upon the ability to decrypt TLS traffic to implement data loss protection, intrusion detection and prevention, malware detection, packet capture and analysis, and DDoS mitigation. Unlike some other businesses, financial institutions also rely upon TLS traffic decryption to implement fraud monitoring and surveillance of supervised employees." I'm at lost here. What…

They key phrase is "rely upon", meaning they went down a route of using a clever hack rather than formally designing a system to meet their goals. I wonder why SOCKs proxies, which every browser supports, wouldn't work for them.

When you use a SOCKS proxy, your traffic is still encrypted from user to server. It wouldn't help them decrypt historic TLS sessions on request.

Re: Industry Concerns about TLS 1.3

#14
post #5

I don't understand why the banks need to change TLS 1.3 to spy on their employees. When I was working at a bank, there were literally no routes from the Intranet to the Internet. Everything went through a proxy that blocked 95% of the Internet. Had to run a proxy server on jrock.us in order to get anything done. (They just bought the list of sites to block, and jrock.us never ended up on it. Blacklisting, very good s…

Who doesn't love a game of wack-a-mole?

Re: Industry Concerns about TLS 1.3

#15
post #3

Well, that was kind of a burn. Was the argument by the bankers basically a complaint that retooling would be very expensive? and/or that employee surveillance would be more difficult? (yeah, I'm sure everyone is a fan of that!)

It sounds like required surveillance though.

The problem here is really they were way, way, behind on getting their concerns out there.

Re: Industry Concerns about TLS 1.3

#17

>>> My view concerning your request: no. is probably the best response for the request. On a related note though, it's always amazing how on one hand Big Banking tries to show that it's in touch with the latest tech developments (Bitcoin Consortiums, RFID/NFC payments) etc. but on the other hand display a very shallow understanding of how secure systems should work.

> display a very shallow understanding of how secure systems should work.

They still ask about mother's maiden name, prevent paste of passwords, took forever to adopt EMV in the US and other idiocies

It's security by cargo-culting

Re: Industry Concerns about TLS 1.3

#18
There are a lot of keyboard warriors in this thread. This guy puts forward a rational argument for big business.

Unless you have extensive experience in this area, perhaps you shouldn't be so quick to judge "oh they are just spying on their users".

The simple answer to this question is that if a way is not given for businesses to decrypt their own traffic that they generated and encrypted, they simply won't encrypt it.

Take this example: A regulation says that all incoming traffic into a banking sector company must be scanned for potential vulnerabilities and exploits, and allows for "compensating controls". If the incoming traffic is unable to be decrypted at TLS1.3, it will simply be decrypted at the boarder of the business and routed internally unencrypted. This would be worse than copying the TLS1.2 traffic for out-of-band scanning.

I'm not saying that this guy wasn't a little late by the party, but failing to recognise that big businesses have regulations you don't understand or even care about is a huge mistake that will make us all more insecure. After all, who doesn't have a bank account?

Re: Industry Concerns about TLS 1.3

#19
post #5

I don't understand why the banks need to change TLS 1.3 to spy on their employees. When I was working at a bank, there were literally no routes from the Intranet to the Internet. Everything went through a proxy that blocked 95% of the Internet. Had to run a proxy server on jrock.us in order to get anything done. (They just bought the list of sites to block, and jrock.us never ended up on it. Blacklisting, very good s…

The guy's rationale may be kind of dubious but it's clearly stated: there aren't any tools that do DPI on TLS 1.3 sessions right now.

Re: Industry Concerns about TLS 1.3

#20
post #18

There are a lot of keyboard warriors in this thread. This guy puts forward a rational argument for big business. Unless you have extensive experience in this area, perhaps you shouldn't be so quick to judge "oh they are just spying on their users". The simple answer to this question is that if a way is not given for businesses to decrypt their own traffic that they generated and encrypted, they simply won't encrypt i…

> After all, who doesn't have a bank account?

But rules and regulations shield me and give me legal and financial aid for the stupid thing my bank might do.

Post reply on HN