Live data from Hacker News

BlueCoat and other proxies hang up during TLS 1.3

bugs.chromium.org

161–170 of 216 posts

Re: BlueCoat and other proxies hang up during TLS 1.3

#161

I guess in future, TLS upgrades will be opt-in?

To explain the other answer a bit more: TLS upgrades have always been opt-in. The problem is that you have to be very clever where you put that option, or some (expensive and popular and dumb) webservers and middleboxes will just freak out and block the client. The obvious place is the TLS version number in the handshake. It can say "I support up to TLS 1.3" and the other side can say "I support up to TLS 1.2" and th…

I wasn't clear, but I meant "opt-in" in the sense that it would be enabled on the client by optional configuration, with big warnings for users on "corporate networks". This would draw attention to the issue, because every time a version bumped the web would be flooded with "be sure and opt in to the TLS upgrade, unless you're on a shitty BlueCoat network!" advice. Eventually BlueCoat would get the message.

I understand that proper network hosts will negotiate TLS versions rather than "freaking out".

Re: BlueCoat and other proxies hang up during TLS 1.3

#162
post #59

Earlier quoted context omitted.

If you're using your company's network, then they have every right to monitor all of the activity on it. This is tantamount to steaming open and resealing the envelopes of all physical mail. Have some god damn ethics, I'd sooner quit than snoop traffic in this manner.

All MITM proxies I know require an enterprise CA trusted by the end-point. If that CA is on your machine the endpoint is probably owned by your employer. It is legal in most jurisdictions for your employer to monitor the usage of resources they have provided, be it computer or network. I would never trust a company device, or company network, with anything I consider sensitive. Use your own device and keep it on cell…

Legal and ethical aren't the same thing, though. I agree it's legal for your employer to monitor traffic on their network. But an ethical sysadmin would not facilitate their doing so (unless there were a fairly significant and unusual justification in context).

(Note: I would also never trust a company device or company network, and I keep my personal devices completely separate from the company network for this reason. But I consider this a workaround for a deplorable situation, rather than just the way things are.)

Re: BlueCoat and other proxies hang up during TLS 1.3

#163

Earlier quoted context omitted.

There's not even a need for installing a proxy! SSH has native SOCKS proxy support, so all you need to do is set up an SSH connection and set the browser connection to a dynamic SSH port forward. This also prevents leaking DNS requests : with a standard proxy your computer might be trying to look up domains using the company DNS system. With a SOCKS proxy, you can forward all DNS traffic as well!

How do you "set the browser connection to a dynamic SSH port forward"?

> ssh -D 4242 user@host

Then in firefox (or other), the socks proxy is on localhost port 4242.

Re: BlueCoat and other proxies hang up during TLS 1.3

#164
Many a head-scratching web application error investigation has resulted in an "a-ha" moment when you notice the `X-BlueCoat-Via` header in your logs. It does stuff like issuing GETs against URLs that only have POST handlers. It issues these random requests having procured its users' auth cookies even when the real user has since left the site.

Re: BlueCoat and other proxies hang up during TLS 1.3

#165
post #105

Earlier quoted context omitted.

Yeah. This is a firable offense. The solution to your company MITM your traffic is not to use your work computer for anything personal that matters. It's not like if we had a shortage of devices to connect to the internet.

If you live in a third-world country (or the US) which lacks basic functions of society like employee protection, a sensible minimum wage, universal healthcare, paid parental leave, etc., then yes, I don't recommend doing what my friend did with employing a little "civil disobedience" in such cases. TBH, for most techies I don't think opposition to MITM boxes comes down to "I don't want them to catch me looking at ca…

> Personally, I would find it unethical for the company I work for to buy these products.

Then leave the company in protest or convince it not to buy them. DDoSing the company's network is somehow not unethical, I guess?

Re: BlueCoat and other proxies hang up during TLS 1.3

#166
post #105

Earlier quoted context omitted.

Yeah. This is a firable offense. The solution to your company MITM your traffic is not to use your work computer for anything personal that matters. It's not like if we had a shortage of devices to connect to the internet.

When I mentioned on a mailing list that we should probably pronounce this like "expect your personal bank info to be pwned" rather than "please don't use work resources for personal purposes", I was reminded that there are lots of perfectly reasonable work-related purposes that are undermined by TLS MitM. Corporate bank accounts, ACH transactions, payroll, vendor accounts, tax portals, employee benefits/401k, etc. Al…

Absolutely, but then the right approach is to let the IT dept know that they are running the company into the ground. Often, the IT department or management may be insensitive to that argument (and then you get a Sony Entertainment hack, but then it is well deserved) or they may follow regulations that are beyond their control. But it is a management decision.

Re: BlueCoat and other proxies hang up during TLS 1.3

#167
post #132

Earlier quoted context omitted.

Reverse-engineer? A middlebox? Which holds trusted secret keys and which, in its normal unremarkable operation, intercepts, parses , reconstructs, decrypts, re-encrypts, forwards, and optionally logs both confidential and attacker-controlled traffic? And is also known to be used for nationwide bulk internet censorship by regimes often called 'oppressive'? Why, doesn't it just. Please consider, very carefully, the eth…

What's true is true - better to know it than stick our heads in the sand. If these boxes have vulnerabilities (who am I kidding, they do parsing, they're probably implemented in C "for performance", of course they have vulnerabilities), we are better off for knowing about them than not.

But what of the equities issue - what to do with that knowledge, once discovered? Might it depend on who "we" are?

My point is that actually helping this particular vendor, for example, may not be everyone's cup of tea.

Re: BlueCoat and other proxies hang up during TLS 1.3

#168

Earlier quoted context omitted.

There was a paper posted on HN a few weeks back by some pretty serious security researchers on the security risks of SSL MITM boxes. https://jhalderm.com/pub/papers/interception-ndss17.pdf How do you fix this when you're naught but a humble employee? Well, a friend of mine worked at a fairly large tech company where a salesguy for these boxes had convinced the CTO they had to have them. Every tech-person "on the floo…

It might backfire and your company forbids HTTPS "so that employees can't disclose company secrets without IT having traceability".

The internet has changed significantly over the last few years and a lot of sites don't support unencrypted connections.

It's pretty entertaining to read this stack overflow questions about using ssl from 7 years ago: http://stackoverflow.com/questions/2177159/should-all-sites-...

Re: BlueCoat and other proxies hang up during TLS 1.3

#169

Earlier quoted context omitted.

Yeah, this is totally not racist in any way. Good to know all the brown people live in "shitholes". Hard to know if this trolling or just casual racism.

You're reading something that isn't there. Russians are like the whitest people on earth. South Korea and Singapore aren't "shitholes" by any measure. However, by their BlueCoat use, they are "wannabe shitholes". I clicked through to find you are "antifa". Didn't you get the memo? You can't be seen to defend Russia in any way!

> I clicked through to find you are "antifa". Didn't you get the memo?

Oh please, most of these people never used their brains to think.

At least, that's my personal experience with them.

Re: BlueCoat and other proxies hang up during TLS 1.3

#170
There is a massive hypocrisy in browser vendors getting hysterical about self signed certs while letting MITM proxies operate with impunity or worse working with them.

Why isn't there an effort to detect MITM proxies and post equally scary warnings? Surely users have a right to know.

MITM is worse than self signed certs and if 'exceptions' can be found for MITM like corporate security, management etc then the same exceptions should be found for self signed certs for individuals rather than creating dependencies on CA 'authorities'. This just another instance of furthering corporate interests while sacrificing individuals.

Post reply on HN