It might weaken TLS, but it also stops the 3000 head of cattle I managed from being able to watch porn (6 incidents) and torrent movies (47 copyright notices). If their internet banking, which they're not supposed to be doing at work, gets compromised then I really couldn't care less.
HTTPS Interception Weakens TLS Security
11–20 of 105 posts
Re: HTTPS Interception Weakens TLS Security
#12I wonder how schools and banks plan to react to this... Apparently financial firms have to record everything their employees do for some regulations.
To me, schools doing this sort of thing is wrong. I wouldn't be surprised if the principle would grab people's passwords and login to their accounts even. I know some schools even went as far to demand students hand over their passwords to social media when they report bullying... Which if the school blocks social networks anyways, I don't see how it's a school issue for what happens outside of school...
If this sort of thing really needs to be done, at-least people should be warned and aware they are being monitored. If it's for a bank and it's only company equipment everything is being monitored it seems a bit more okay to do if everyone is well aware. "You are only to use work computers for official business." sort of policy.
Re: HTTPS Interception Weakens TLS Security
#13The US government has basically declared "HTTPS/TLS Interception Considered Harmful". This is going to be interesting as all the major security load blanacer/appliances out there offer this as a standard service at this point.
As far as I can tell this is targetted at what I would expect: "antivirus" and compliance tools built into firewalls, not reverse proxies built into load balancers.
Re: HTTPS Interception Weakens TLS Security
#14It does not have to be. Done correctly, SSL interception can pass through all the errors to the client: * certificate issues (expiration, domain mismatch, etc.) * OCSP/CRL verification * validation of HPKP header I understand that few vendors may be doing it (I know one which does at least the first 2). Probably the worst offense is choosing the weakest TLS version + cipher to save resources, like using TLS 1.0 becau…
On the other hand, a MITM proxy can also do upgrade "attacks"(?!), communicating with remote servers over the Internet using a stronger protocol than the clients on the LAN behind it support. In fact it seems to me that having the validation happening in one place may potentially be easier to maintain than across many different clients' software.
Re: HTTPS Interception Weakens TLS Security
#15A while back I remember seeing on HN there was a issue with a certain vendor and ChromeBooks because Chrome used a newer TLS(And the mitm vendor vendor was noticed in advance too, and didn't update their product). I wonder how schools and banks plan to react to this... Apparently financial firms have to record everything their employees do for some regulations. To me, schools doing this sort of thing is wrong. I woul…
Phone calls, emails, instant messages and other forms of client contact, yes. Internet browsing history? No. Rest assured, many firms do this. But it's because they decided to, not because of regulation.
Re: HTTPS Interception Weakens TLS Security
#16It might weaken TLS, but it also stops the 3000 head of cattle I managed from being able to watch porn (6 incidents) and torrent movies (47 copyright notices). If their internet banking, which they're not supposed to be doing at work, gets compromised then I really couldn't care less.
Re: HTTPS Interception Weakens TLS Security
#17TL;DR: If your organization is going to do HTTPS interception, don't screw it up .
Re: HTTPS Interception Weakens TLS Security
#18It might weaken TLS, but it also stops the 3000 head of cattle I managed from being able to watch porn (6 incidents) and torrent movies (47 copyright notices). If their internet banking, which they're not supposed to be doing at work, gets compromised then I really couldn't care less.
Instead couldn't you just whitelist the online banking sites and intercept everything else?
Re: HTTPS Interception Weakens TLS Security
#19A while back I remember seeing on HN there was a issue with a certain vendor and ChromeBooks because Chrome used a newer TLS(And the mitm vendor vendor was noticed in advance too, and didn't update their product). I wonder how schools and banks plan to react to this... Apparently financial firms have to record everything their employees do for some regulations. To me, schools doing this sort of thing is wrong. I woul…
> financial firms have to record everything their employees do for some regulations Phone calls, emails, instant messages and other forms of client contact, yes. Internet browsing history? No. Rest assured, many firms do this. But it's because they decided to, not because of regulation.
Re: HTTPS Interception Weakens TLS Security
#20It might weaken TLS, but it also stops the 3000 head of cattle I managed from being able to watch porn (6 incidents) and torrent movies (47 copyright notices). If their internet banking, which they're not supposed to be doing at work, gets compromised then I really couldn't care less.
Instead couldn't you just whitelist the online banking sites and intercept everything else?