Live data from Hacker News

Industry Concerns about TLS 1.3

ietf.org

61–70 of 194 posts

Re: Industry Concerns about TLS 1.3

#61

"...almost all of whom are running TLS internally and have significant, security-critical investments in out-of-band TLS decryption. Like many enterprises, financial institutions depend upon the ability to decrypt TLS traffic to implement data loss protection, intrusion detection and prevention, malware detection, packet capture and analysis, and DDoS mitigation. Unlike some other businesses, financial institutions a…

Only sometimes. The argument here could be whether you, as an individual working for an employer on employer-controlled hardware, have the right to communications that cannot be viewed by the employer at their discretion on those systems. Having that capability (undecryptable communication) on an exceptional basis (e.g. only a few sites or methods do it) might be grounds for blocking any instances of the protocol tha…

From a technical standpoint, the desire of to monitor all communications of a stockbroker in an easy and effective manner and being able to decrypt historical captured is identical to the desire of to do the same for their civil rights activists.

From a protocol perspective, you can't distinguish it - any new protocol either makes monitoring harder for everyone or easier for everyone, without checking if your reason is good or bad.

If we choose to make communications more private, then yes, the ability to monitor stuff will suffer even if someone has a legitimate and reasonable reason to need this ability. Too bad, we've made a choice that the security of the masses is more important than this. I acknowledge that this change will hurt the banks for the reasons given above, but in this case hurting them is an unavoidable cost of helping most everyone else.

Re: Industry Concerns about TLS 1.3

#62

Earlier quoted context omitted.

> Take this example: A regulation says that all incoming traffic into a banking sector company must be scanned for potential vulnerabilities and exploits, and allows for "compensating controls". If the incoming traffic is unable to be decrypted at TLS1.3, it will simply be decrypted at the boarder of the business and routed internally unencrypted. Sorry, I don't get it. All encrypted traffic is typically decrypted by…

The guy is basically complaining that they have to change all their infra over to MITM versus just decrypting traffic with private keys. He is right, it will be expensive. And he has a right to complain. Should the working group ignore him? It's a tough call. You risk forking standards when you start to do that.

I think the working group should ignore him because he ultimately wants to save a buck now and shoot himself in the foot, he just doesn't realize it yet.

The enterprise as walled garden approach to security seems quite out of date and is harmful to all parties involved. Like it or not, the Internet at large has made our life one big WAN party, and we need to come to terms with that sooner rather than later.

Re: Industry Concerns about TLS 1.3

#63
post #18

There are a lot of keyboard warriors in this thread. This guy puts forward a rational argument for big business. Unless you have extensive experience in this area, perhaps you shouldn't be so quick to judge "oh they are just spying on their users". The simple answer to this question is that if a way is not given for businesses to decrypt their own traffic that they generated and encrypted, they simply won't encrypt i…

So my knowledge about how forward secrecy works in TLS is spotty to say the least but the server still has the decryption key in memory AFAIK. Why not sidestep the issue and just create a secure channel between the server and whatever middleboxes there are that need the key and just send the ephemeral key that way?

I get that this would be less secure to use in practice because now anyone who gets control over the server or the middleboxes or who can somehow compromise that secure channel between them can get at the shared secret but still, it would preserve forward secrecy. The only caveat is that the secure channel between the server and the middleboxes would also need forward secrecy but I don't really see how that is a problem.

Am I missing something obvious here?

Re: Industry Concerns about TLS 1.3

#64
post #57
post #55

Earlier quoted context omitted.

So much worse with NFC, where I can just tap my card (or my phone) against the reader and be done. Further, you always had to wait for the cashier to scan everything in the UK. The 'magic button' is an implementation detail and not native to the technology. But apart from that, sure, you want an easily-cloneable passive technology because it saves you a few seconds under some circumstances.

> Further, you always had to wait for the cashier to scan everything in the UK. But not in the US. This is also just an "implementation detail". But implementation details are essential for the user experience. > you want an easily-cloneable passive technology because it saves you a few seconds under some circumstances. Exactly, convenience trumps everything. At the end of the day, I don't lose any money with the les…

> At the end of the day, I don't lose any money with the less secure technology. The bank does. Why should I care?

Apparently you never had a card skimmed

1 - Your card is cancelled and you have to wait some days for a replacement (requiring also that you update it everywhere)

2 - The money you lost (in case of debit) will get back to you, after an investigation.

Re: Industry Concerns about TLS 1.3

#65
post #18

There are a lot of keyboard warriors in this thread. This guy puts forward a rational argument for big business. Unless you have extensive experience in this area, perhaps you shouldn't be so quick to judge "oh they are just spying on their users". The simple answer to this question is that if a way is not given for businesses to decrypt their own traffic that they generated and encrypted, they simply won't encrypt i…

With regards to your example, in my experience in the banking industry, you just re-encrypt for the internal leg. TBH I think the BITS guy is over-egging his case a fair bit. For all outbound to Internet comms they've got to use an interecepting proxy anyway 'cause they're unlikely to have the relevant private key for the communication. So those systems are in place already. For inbound comms sure there's a hit, you'…

Yeah, but this means you end up with all this communication infrastructure with MITM or DMZ termination of ssl. Is that really going to be more secure than just allowing for non forward secrecy? Just because the working group removes non forward secrecy from tls doesn't mean it's going to make things better.

Re: Industry Concerns about TLS 1.3

#66

Earlier quoted context omitted.

> Take this example: A regulation says that all incoming traffic into a banking sector company must be scanned for potential vulnerabilities and exploits, and allows for "compensating controls". If the incoming traffic is unable to be decrypted at TLS1.3, it will simply be decrypted at the boarder of the business and routed internally unencrypted. Sorry, I don't get it. All encrypted traffic is typically decrypted by…

The guy is basically complaining that they have to change all their infra over to MITM versus just decrypting traffic with private keys. He is right, it will be expensive. And he has a right to complain. Should the working group ignore him? It's a tough call. You risk forking standards when you start to do that.

It will be expensive, but there's a big market for that. I'm pretty sure that the costs will fall, as soon as the industry understands the demand.

Re: Industry Concerns about TLS 1.3

#67
post #57

Earlier quoted context omitted.

> Further, you always had to wait for the cashier to scan everything in the UK. But not in the US. This is also just an "implementation detail". But implementation details are essential for the user experience. > you want an easily-cloneable passive technology because it saves you a few seconds under some circumstances. Exactly, convenience trumps everything. At the end of the day, I don't lose any money with the les…

> At the end of the day, I don't lose any money with the less secure technology. The bank does. Why should I care? Apparently you never had a card skimmed 1 - Your card is cancelled and you have to wait some days for a replacement (requiring also that you update it everywhere) 2 - The money you lost (in case of debit) will get back to you, after an investigation.

> Apparently you never had a card skimmed

I did! Just a few days ago! And it's a chip card, but doesn't matter since the skimmer used the information in the magstripe online.

> Your card is cancelled and you have to wait some days for a replacement (requiring also that you update it everywhere)

The new card arrived minutes ago! And that only because they had to send it to a different country. I would have gotten one the same day if I wouldn't have been abroad.

This is the reason why I have multiple cards, and why I never mix up the cards I use online, with the cards I use physically at the store. Since the card that was skimmed was one that I used physically, I didn't have to change it anywhere. And in the meantime, I had backup cards. Always have backup cards and backup banks.

> The money you lost (in case of debit) will get back to you, after an investigation.

Nope. The money was returned instantly. In fact, the bank realised what was going on and reversed all transaction before even calling me.

If my bank didn't do these basic things I would chose a different bank.

Re: Industry Concerns about TLS 1.3

#68
post #29

Earlier quoted context omitted.

You don't need to do deep packet inspection when you just MITM all the traffic.

MITM introduces significant delays, yet another single point of failure, adds significant risk of leakage. Current DPI are passive, so they have no such problems.

It's technical problem, that can be solved. Dedicated hardware optimized for MITM, probably.

Re: Industry Concerns about TLS 1.3

#69
post #27
post #20

Earlier quoted context omitted.

> After all, who doesn't have a bank account? But rules and regulations shield me and give me legal and financial aid for the stupid thing my bank might do.

True enough. But those who steal your account information and use it to pose as you don't follow the rules and regulations.

And how does that relate to the fact that banks would like to have a weaker version of TLS 1.3? If a nefarious entity is stealing your data they're (probably) MITMing your connection with the bank, in which case TLS 1.3 is likely an improvement for you and the bank and so is the forward secrecy part. If it's more along the lines of social engineering then the whole TLS thing becomes moot.

Sure they might be inside the bank's network in which case being able to more easily decrypt traffic could help in sighting this kind of activity, but there's easier ways of stealing people's data and impersonating them than infiltrating a bank.

Re: Industry Concerns about TLS 1.3

#70
post #67

Earlier quoted context omitted.

> At the end of the day, I don't lose any money with the less secure technology. The bank does. Why should I care? Apparently you never had a card skimmed 1 - Your card is cancelled and you have to wait some days for a replacement (requiring also that you update it everywhere) 2 - The money you lost (in case of debit) will get back to you, after an investigation.

> Apparently you never had a card skimmed I did! Just a few days ago! And it's a chip card, but doesn't matter since the skimmer used the information in the magstripe online. > Your card is cancelled and you have to wait some days for a replacement (requiring also that you update it everywhere) The new card arrived minutes ago! And that only because they had to send it to a different country. I would have gotten one…

Ah so apparently you have American bank cards

This is more complicated when you're a tourist

You know in Europe people don't have many cards. Some people use a prepaid one for online transactions (not only for fraud but also for "things I suspect I might get overcharged")

(I also don't want to swipe my card before I know how much they're charging for it, so I'll wait for everything to give them my card)

Don't dismiss it as "the bank pays for it", I know banks get big profits, but guess where they money come from.

Post reply on HN