Live data from Hacker News

HTTPS Interception Weakens TLS Security

us-cert.gov

101–105 of 105 posts

Re: HTTPS Interception Weakens TLS Security

#101
post #9

It might weaken TLS, but it also stops the 3000 head of cattle I managed from being able to watch porn (6 incidents) and torrent movies (47 copyright notices). If their internet banking, which they're not supposed to be doing at work, gets compromised then I really couldn't care less.

You need to re-read the standard sudo lecture.

Re: HTTPS Interception Weakens TLS Security

#102
One important reason to do ssl inspection is to detect the exfiltration of corporate data, particularly if your organisation is likely to be attacked by governments or sophisticated crime gangs.

I know my organisation do SSL inspection, but they have whitelisted common personal websites like internet banking to protect the privacy of staff.

As far as I'm concerned, if your risk profile requires you to do SSL inspection then this is the right way to do it.

Re: HTTPS Interception Weakens TLS Security

#103
post #68
post #10

Reading the title ... no shit.

Exactly my idea, but after reading the article I'm severely disappointed that the whole practice isn't declared bad. Instead it only points out that some mitm boxes are even more broken than I though possible and mess up cert validation.

It's a terrible practice, the article doesn't even go into some other things like how easy is it to actually break into the intercepting software and steal the private cert so you can mitm the network for free!

and I'm a dev at one of these companies!

We really didn't want to add the feature but we were bleeding customer's who for some reason had to have it. ( Yes, we do validate the certificates )

We decided to bite the bullet when it looked like even Google was "supporting" being mitmed as a customer pointed out.

Reading this article... https://support.google.com/a/answer/1668854?hl=en

was my biggest "fuck you" moment.

Re: HTTPS Interception Weakens TLS Security

#104
post #9

It might weaken TLS, but it also stops the 3000 head of cattle I managed from being able to watch porn (6 incidents) and torrent movies (47 copyright notices). If their internet banking, which they're not supposed to be doing at work, gets compromised then I really couldn't care less.

1. Snooping on their internet banking is ILLEGAL for you to do and puts YOU in hot water. You realize you could be put out of business by lawsuits right?

Really, got any references for that? Specifically Australian law please.

Re: HTTPS Interception Weakens TLS Security

#105

Earlier quoted context omitted.

Worked for Big 4. They did not log my phone calls or sniff my TLS traffic.

If you went through a proxy, they almost certainly did.

They didn't install TLS certs on my machine. My certs were the same ones I see on my home PC.
Post reply on HN