Stop Breaking TLS
31–40 of 175 posts
Re: Stop Breaking TLS
#32> Consider this - what is the likelihood of every certificate authority on the Internet having their private keys compromised simultaneously? I’d wager that’s almost at the whatever is the statistics equivalent of the Planck length level of probability. It doesn't matter if every certificate authority is compromised or just one. One is all that is needed to sign certificates for all websites.
Re: Stop Breaking TLS
#33I largely agree with the author. When our SOC wanted to implement TLS inspection I blocked it. Mostly because we not nearly at the security level for this, but also because it just fucks with so many things. That said, we are not a business dealing with highly sensitive data or legal responsibilities surrounding data loss prevention. If you are a business like that, say a bank or a hospital, you want to be able to bl…
Oh and the software (Netskope) was only able to decrypt our traffic in the cloud . Lmao not in a million fucking years will I upload our data to an American company in fucking plaintext.
On the other hand I am sympathetic to the needs of big regulated orgs to show they're doing something to avoid data loss. It's a painful situation.
Re: Stop Breaking TLS
#34Earlier quoted context omitted.
Author here, hi! Was just venting last night, but that's a very good point, I'll update it later with your correction :)
You should make it about CT logs. I believe you need to compromise at least three of them.
It is striking that we don't see that. We reliably see people saying "obviously" the Mossad or the NSA are snooping but they haven't shown any evidence that there's tampering
Re: Stop Breaking TLS
#35Because the Framework laptop site at frame.work is malicious, of course.
God, I love CURLing crap from my workstation and not getting the files I needed but instead a bunch of mangled HTML telling me zScaler was going to scan what I was going to download.
Bonus points that it puts me in the wrong country because I’m closer to Montreal than any American locations so half the time I’m stuck in French Canadian on the web from my New York office.
Triple bonus points that I’m required to test speed at client sites and zScaler completely mangles our presentable results.
Quadruple bonus points that I put in "because I feel like it" into every elevation request I make on my corporate machine and our "cyber team" has literally never looked at elevation reports to ask what the hell I'm doing...
Re: Stop Breaking TLS
#36Complains about TLS inspection, yet fronts their website on the biggest and most widely deployed TLS introspection middle box in the world ... Why do we all disdain local TLS inspection software yet half the Internet terminates their TLS connection at Cloudflare who are most likely giving direct access to US Intelligence? It's so much worse as it's infringing on the privacy and security of billions of innocent people…
TLS inspection is for EVERYTHING in your network, not just your publicly reachable URLs.
Putting Cloudflare anti-DDoS in front of your website is not the same as breaking all encryption on your internal networks.
Google can already see the content of this site since it's hosted... on the internet.
Re: Stop Breaking TLS
#37Considering that CloudFlare has managed to MitM a huge part of the internet, I'd say that probability is not just non-zero, but greater than by a worrying margin.
Re: Stop Breaking TLS
#38The fact that most tools have completely different ways to allow them to add certificates is the biggest pain. Git, Python and Rust also have large issues. Git doesn't default to "http.schannel". Python (or rather requests, or maybe urllib3) only looks at its own certificate store, and I have no idea how Rust does this (well, I use uv, and it has its own problems - I know about the --use-native-tls flag, but it shoul…
It added huge amounts of friction which was one reason I decided to move on from that gig.
Re: Stop Breaking TLS
#39Earlier quoted context omitted.
In Europe they prefer not to go to jail for privacy violations. It turns out most of these "communist" regulations are actually pretty great.
Does GDPR (or similar) establish privacy rights to an employee’s use of a company-owned machine against snooping by their employer? Honest question, I hadn’t heard of that angle. Can employers not install EDR on company-owned machines for EU employees?
Using a device owned by your company to access your personal GMail account does NOT void your legal right to privacy.
Re: Stop Breaking TLS
#40Complains about TLS inspection, yet fronts their website on the biggest and most widely deployed TLS introspection middle box in the world ... Why do we all disdain local TLS inspection software yet half the Internet terminates their TLS connection at Cloudflare who are most likely giving direct access to US Intelligence? It's so much worse as it's infringing on the privacy and security of billions of innocent people…
Who needs to let CF directly onto their network when they already sit between client and provider for critically-private, privileged communications and records access?