Live data from Hacker News

Deep packet inspection is dead, and here's why (2017)

security.ias.edu

1–10 of 126 posts

Re: Deep packet inspection is dead, and here's why (2017)

#2
Not a very informative article. All it manages to say is that deep packet inspection does not work with encrypted traffic. I think author is not aware of transparent deep packet inspection of SSL traffic. Here is one such product doing it.

https://www.sonicwall.com/en-us/products/firewalls/security-...

Re: Deep packet inspection is dead, and here's why (2017)

#4

Not a very informative article. All it manages to say is that deep packet inspection does not work with encrypted traffic. I think author is not aware of transparent deep packet inspection of SSL traffic. Here is one such product doing it. https://www.sonicwall.com/en-us/products/firewalls/security-...

The article describes such products, so the author clearly is aware of their existence.

Re: Deep packet inspection is dead, and here's why (2017)

#6

Not a very informative article. All it manages to say is that deep packet inspection does not work with encrypted traffic. I think author is not aware of transparent deep packet inspection of SSL traffic. Here is one such product doing it. https://www.sonicwall.com/en-us/products/firewalls/security-...

Actually, that's kind of what the whole of the second half of the article is about.

Re: Deep packet inspection is dead, and here's why (2017)

#7

Not a very informative article. All it manages to say is that deep packet inspection does not work with encrypted traffic. I think author is not aware of transparent deep packet inspection of SSL traffic. Here is one such product doing it. https://www.sonicwall.com/en-us/products/firewalls/security-...

That’s just a run-of-the-mill MITM privacy violator

Re: Deep packet inspection is dead, and here's why (2017)

#9
post #5

The author suggests towards the end to analyze DNS queries, but that's on the best way [1] to be encrypted as well (finally). [1] https://wiki.mozilla.org/Trusted_Recursive_Resolver

In a corporate environment, managed devices can be configured to force the use of specific DNS settings. The same type of implementation (MITM) could be used to analyse the requests.

That being said, this is at the OS level. An app such as Firefox could still override those settings or provide their own implementation.

Re: Deep packet inspection is dead, and here's why (2017)

#10
post #9
post #5

The author suggests towards the end to analyze DNS queries, but that's on the best way [1] to be encrypted as well (finally). [1] https://wiki.mozilla.org/Trusted_Recursive_Resolver

In a corporate environment, managed devices can be configured to force the use of specific DNS settings. The same type of implementation (MITM) could be used to analyse the requests. That being said, this is at the OS level. An app such as Firefox could still override those settings or provide their own implementation.

If you IT department is your adversary you should get a new job. Or at least use a personal device for personal matters :)
Post reply on HN