Live data from Hacker News

Industry Concerns about TLS 1.3

ietf.org

121–130 of 194 posts

Re: Industry Concerns about TLS 1.3

#121
post #18

There are a lot of keyboard warriors in this thread. This guy puts forward a rational argument for big business. Unless you have extensive experience in this area, perhaps you shouldn't be so quick to judge "oh they are just spying on their users". The simple answer to this question is that if a way is not given for businesses to decrypt their own traffic that they generated and encrypted, they simply won't encrypt i…

It does indeed make sense from his point of view. Unfortunately, there are some actors using the exact same perimeter "defense" who I'd gladly see frustrated, mostly governments east of of Poland.

I'm also hopeful that an increase in price of any MITM solutions that might get develop will put an end to such practices where they are abused for marginal utility: Universities, Hotels, Airports, ad-replacing proxies etc.

Re: Industry Concerns about TLS 1.3

#122
post #103
post #96

Earlier quoted context omitted.

Because why? The idea that an organization shots be able to monitor its own traffic seems quite reasonable to me.

But the organization already can monitor its own traffic. At the source, before it is encrypted.

Unless the devices that need to be monitored are the endpoints. Do you really oppose the laws requiring banks to record all communication (including non-official channels) that goes in and out of their trader's computers? Or do you have an alternate solution that doesn't make circumventing it dramatically easier?

Re: Industry Concerns about TLS 1.3

#123
This is exactly the clash between governments (here financial regulation) and cyberlibertarians I wrote about earlier this year:

http://queue.acm.org/detail.cfm?id=2904894

What have we gained in security, if TLS1.3 is basically illegal to use for banks ?

Who wins if browsers refuses to connect to web-banking which operates inside the boundaries of the law ?

Re: Industry Concerns about TLS 1.3

#124
post #18

There are a lot of keyboard warriors in this thread. This guy puts forward a rational argument for big business. Unless you have extensive experience in this area, perhaps you shouldn't be so quick to judge "oh they are just spying on their users". The simple answer to this question is that if a way is not given for businesses to decrypt their own traffic that they generated and encrypted, they simply won't encrypt i…

While I probably (haven't followed the issue closely) agree with him on the issue, the arrogance makes my blood boil. These academics and their dysfunctional standard agencies are the ones that should go down in history for how intelligence agencies could build unprecedented dossiers on civilians and despots could enforce their will by torturing journalists. If he thinks one can make a secure internet, something his organization has repeatedly shown itself incapable of doing, without having major players on board with your decisions he is delusional at best.

Re: Industry Concerns about TLS 1.3

#125
post #86
post #77

Earlier quoted context omitted.

Because otherwise the consumer pays for the fraud and the insurance anyway. Why do you think US credit card transaction fees to merchants are so damn high?

> Why do you think US credit card transaction fees to merchants are so damn high? Because until recently, the law was that merchants were not allowed to charge discriminatively based on cash vs. card. Since americans love their CCs and unlike in Europe, CCs are a massive part of retail sales, it was not too difficult for the credit card mafia to impose whatever fees on merchants. Here in Europe, fees are capped throu…

The fraud profile is absolutely not the same in the EU and the US, where cloned cards are frequently used to withdraw cash and make physical purchases.

Yes, fees in the EU are capped by law, but to think cards are not used just as much used in places like the UK as they are in the US ... Have you been living under a rock for 30 years?

And no, the chip doesn't protect online, other features do.

One way or another, the US consumer pays for the much higher levels of fraud that the stripe allows.

Re: Industry Concerns about TLS 1.3

#126
post #18

There are a lot of keyboard warriors in this thread. This guy puts forward a rational argument for big business. Unless you have extensive experience in this area, perhaps you shouldn't be so quick to judge "oh they are just spying on their users". The simple answer to this question is that if a way is not given for businesses to decrypt their own traffic that they generated and encrypted, they simply won't encrypt i…

Implementing an official Bump-in-the-wire MITM method for TLS would be the final nail in the coffin of the protocol; nobody would take it seriously and would move onto IPSEC.

If big business needs to secure communications in and out of the enterprise, then they need to stop being lazy about it. Tap the endpoints and use internet proxies, block communications with unapproved websites, and install surveillance gear in the conference rooms. I get these are costly measures, but they are only costly because of input cost to get there, not operating cost.

Want to know how you get a gargantuan database out of any company? Ship it out the firewall through a client PC as a H.323 video stream through your favorite software package. You tell me how to filter that one on a modern, carrier grade Pal-Alto firewall? We have tremendous holes in the existing infrastructure because we don't want to put the work into actual security or into fundamental theory.

The bias here is the market should slow down for big business, the reality is, big business not being on the ball and putting pressure for changes on a protocol like this is a tremendous subsidy to those companies. Frankly, public sediment is right in this case, the big businesses should bare the brunt and cost of their mistakes.

Re: Industry Concerns about TLS 1.3

#127
post #80
post #71

Earlier quoted context omitted.

No. Convenience doesn't trump everything, economics does. Banks with better security can offer cheaper services to merchants, and the merchants lower prices to the customer. You don't lose money with the stripe in the US because the banks eat the (massive) losses. Here they don't, because of the better tech. You can still use the stripe, but the merchant takes the liability. It's up to them. Guess why they don't... S…

> Banks with better security can offer cheaper services to merchants Yeah, like we know that will ever happen. > economics Then let the banks allow people to chose what type of card they want, allow merchants to charge different price based on the type of card, allow merchants to implement paying before scanning, etc. Basically, allow the economy to work. The system works the way it works (in any country) because of…

Yeah, the banks are totally going to offer a fraud-prone product for morons who want to pay higher prices and save 2 seconds. This is nonsense.

You have to wait for the transaction to go through regardless. With a chip you just have to wait before removing the card, as a security feature.

Re: Industry Concerns about TLS 1.3

#128
post #18

There are a lot of keyboard warriors in this thread. This guy puts forward a rational argument for big business. Unless you have extensive experience in this area, perhaps you shouldn't be so quick to judge "oh they are just spying on their users". The simple answer to this question is that if a way is not given for businesses to decrypt their own traffic that they generated and encrypted, they simply won't encrypt i…

Implementing an official Bump-in-the-wire MITM method for TLS would be the final nail in the coffin of the protocol; nobody would take it seriously and would move onto IPSEC. If big business needs to secure communications in and out of the enterprise, then they need to stop being lazy about it. Tap the endpoints and use internet proxies, block communications with unapproved websites, and install surveillance gear in…

I agree, this isn't a low margin business either. We are talking about inferior security for all internet users for the sake of Well Fargo's quarterly report.

Re: Industry Concerns about TLS 1.3

#129
post #103

Earlier quoted context omitted.

But the organization already can monitor its own traffic. At the source, before it is encrypted.

Unless the devices that need to be monitored are the endpoints. Do you really oppose the laws requiring banks to record all communication (including non-official channels) that goes in and out of their trader's computers? Or do you have an alternate solution that doesn't make circumventing it dramatically easier?

I'm not sure I follow what you're saying. I'm arguing that the banks should already be in full control of their endpoints, so I don't see why they can't perform the monitoring there. Nor do I think that banks should be facilitating the use of non-official channels for communication.

As for circumvention: are you concerned about ensuring a complete communication paper trail or protection from insider threats?

Re: Industry Concerns about TLS 1.3

#130
post #50
post #32

Earlier quoted context omitted.

But the bank follows the regulations that tell it to give me all my money back, if there's some fraud. I don't have any money to lose if the bank does not implement security properly. Only the bank has to lose.

They'll refund you after you've already lost the money, or the attacker might use the bank details as part of larger-scale identity theft that might come to leave you in hot water with law enforcement if he uses your identity to commit a crime. All that inconvenience is your own loss, and the bank paying damages for that doesn't really "fix it"

>leave you in hot water with law enforcement if he uses your identity to commit a crime.

Officer Friendly: His social security card was found at the scene, so Mr.Smith must be guilty!

Post reply on HN