Live data from Hacker News

You have a moral obligation to use crypto

blog.easydns.org

91–92 of 92 posts

Re: You have a moral obligation to use crypto

#91

Earlier quoted context omitted.

I know I've heard about this somewhere before, but it seems to me somewhat a hassle to setup MITM attacks if you already have admin access over all the machines. Just put a browser plugin that logs everything and lock down the machines to they can't be messed with by non-admins. Corporate employees are generally not allowed to admin their own machines or expect any privacy on them - so there's no point in hiding the…

https://www.imperialviolet.org/2011/05/04/pinning.html https://www.net-security.org/secworld.php?id=12369 https://news.ycombinator.com/item?id=5141342 I'm pretty sure it happens, trustwave apparently issued a cert for these purposes and it's claimed other CA's have done the same. It's a hassle to do, but the goal is to detect and prevent corporate espionage. Most corporates have their own OS media - installing from o…

I remember reading about that trustwave incident, that is definitely messed up!

I was just really trying to say that adding a rogue CA to the browser trust list vs installing a plugin both require admin permission and are both "noticeable." So neither of them are really ideal for serious espionage. In which case they're only good for non-secret employee monitoring. So, in that case, might as well go with a plugin because it would be the simpler solution.

If you're talking about a compromised "root" CA like trustwave or something where a stock browser will trust fake certs - now you're talking about a technique suitable for espionage or black hat activities.

Re: You have a moral obligation to use crypto

#92

Earlier quoted context omitted.

https://www.imperialviolet.org/2011/05/04/pinning.html https://www.net-security.org/secworld.php?id=12369 https://news.ycombinator.com/item?id=5141342 I'm pretty sure it happens, trustwave apparently issued a cert for these purposes and it's claimed other CA's have done the same. It's a hassle to do, but the goal is to detect and prevent corporate espionage. Most corporates have their own OS media - installing from o…

I remember reading about that trustwave incident, that is definitely messed up! I was just really trying to say that adding a rogue CA to the browser trust list vs installing a plugin both require admin permission and are both "noticeable." So neither of them are really ideal for serious espionage. In which case they're only good for non-secret employee monitoring. So, in that case, might as well go with a plugin bec…

A browser plugin is really really obvious, whereas if you take a look at the CA's in firefox - there's hundreds. All you need is one subtly different from what's expected - barely noticeable.

https://www.bluecoat.com/products/proxysg

I think you'll find the above product interesting. Apparently anti-virus vendors have similar programs - to prevent malware being downloaded over https behind a corporate proxy.

It seems that CDN's such as cloudflare and akamai take the websites SSL _private_ keys too.

http://blog.cloudflare.com/introducing-strict-ssl-protecting...

This blog post is a fancy way of saying that cloudflare content serving customers now have the option of encrypting the link between cloudflare and them. Note that users can still be MITM'd at the cloudflare site - even with the new arragement.

Post reply on HN