Live data from Hacker News

Stop Breaking TLS

markround.com

161–170 of 175 posts

Re: Stop Breaking TLS

#161

Earlier quoted context omitted.

That's the most naive take I've read online this year. So your stance is that spy agencies aren't spying on us because if they were, we'd know about it?

Your "I bet they're God" stance is even more naive. They're not God, they've got a finite budget both in financial terms and in terms of what will be tolerated politically. Of course spooks expend resources to spy on people, but that's an expenditure from their finite budget. If it costs $1 to snoop every HTTP request a US citizen makes in a year, that's inconsequential so an NSA project to trawl every such request g…

That's never been my stance because there's a difference between mass surveillance and targeted surveillance. If you understood that then you wouldn't be getting lost and making silly references to "God".

I don't believe that the NSA is omniscient. I believe they have 95% of data on 95% of the population through mass surveillance, and 99.9% of data on 99.9% of people of interest through targeted surveillance.

You think abusing public CAs for mass surveillance is a genius idea, and that its lack of real-world abuse proves that mass surveillance just doesn't happen - full stop.

Unfortunately you fail to consider that if they tried to do this just once, they would be detected immediately, offending CAs would be quickly removed from every OS and browser on the planet, the trust in our digital infrastructure would be eroded, impacting the economy, and it would likely all be in exchange for nothing.

On the other hand if you're trying to target someone then what's the point of using an attack that immediately tips off your target, that requires them to be on a network path that you control, and that's trivially defeated if they simply use a VPN or any sort of application-layer encryption, like Signal? There is none.

Re: Stop Breaking TLS

#162

Earlier quoted context omitted.

That's probably because there is no answer. Many laws apply to the total thing you are creating end-to-end. Even the most basic law like "do not murder" is not "do not pull gun triggers" and a gun's technical reference manual would only be able to give you a vague statement like "Be aware of local laws before activating the device." Legal privacy is not about whether you intercept TLS or not; it's about whether someo…

Okay, thanks for explaining the general concept of law to me, but this provides literally no information to figure out the conditions under which an employer using a TLS intercepting proxy to snoop on the internet traffic a work laptop violates GDPR. I never asked for a definitive answer just, you know, an answer that is remotely relevant to the question. I don’t really need to know, but a bunch of people seemed real…

Are they using it to snoop on the traffic, or are they merely using it to block viruses? Lack of encryption is not a guarantee of snooping. I know in the USA it can be assumed that you can do whatever you want with unencrypted traffic, which guarantees that if your traffic is unencrypted, someone is snooping on it. In Europe, this might not fly outside of three-letter agencies (who you should still be scared of, but they are not your employer).

Re: Stop Breaking TLS

#163
post #93

Earlier quoted context omitted.

Would it be hard? I thought the point of tailscale was not having to manage or concern yourself with key distribution.

Lookup the Tailnet Lock feature.

A feature in the client software they control, that you run as root, that auto-updates regularly?

Re: Stop Breaking TLS

#164
post #154

Earlier quoted context omitted.

IP level blocks will work fine for that

Blocking IPs hasn’t worked well since the 2000s: if you block CDNs, you’ll find out how many legitimate services use the same CDN.

Yes. And malicious egress traffic (bad actors or malware exfiltrating data) typically routes to deliberately-unpredictable and constantly changing IPs.

Like, I don't love TLS MITM-ing. It's not a good thing. But it's the least bad of the options available for solving a problem that many people have decided must be solved (regulating behavior on a LAN).

Re: Stop Breaking TLS

#165

Earlier quoted context omitted.

Your "I bet they're God" stance is even more naive. They're not God, they've got a finite budget both in financial terms and in terms of what will be tolerated politically. Of course spooks expend resources to spy on people, but that's an expenditure from their finite budget. If it costs $1 to snoop every HTTP request a US citizen makes in a year, that's inconsequential so an NSA project to trawl every such request g…

That's never been my stance because there's a difference between mass surveillance and targeted surveillance. If you understood that then you wouldn't be getting lost and making silly references to "God". I don't believe that the NSA is omniscient. I believe they have 95% of data on 95% of the population through mass surveillance, and 99.9% of data on 99.9% of people of interest through targeted surveillance. You thi…

> They either have a backdoor, or have the capability to add a backdoor in the hardware that generates those keys in the first place

> That's never been my stance

It took you about a day to go from being absolutely sure of a thing, to absolutely sure you've never believed that thing.

Re: Stop Breaking TLS

#166

The author is complaining a lot about implementation pains without taking a step back and looking at why it exists in the first place. Say you work at a place that deals with credit cards. You, as a security engineer, have a mandate to stop employees from shipping CC numbers outside the org. You can educate all you want, you can have scary policies and HR buy-in, you can have all the "Anomaly detection, Zero Trust ne…

> stop Joe Lunchbox from copy/pasting a block with a CC number in the middle into ChatGPT. You know what will? A TLS-inspecting proxy with some DLP bits and bobs.

If you are sniffing web traffic for anything that looks like a credit card number, won't you just catch every time the employee/company's own card is entered onto a payment page?

Re: Stop Breaking TLS

#167

Earlier quoted context omitted.

That's never been my stance because there's a difference between mass surveillance and targeted surveillance. If you understood that then you wouldn't be getting lost and making silly references to "God". I don't believe that the NSA is omniscient. I believe they have 95% of data on 95% of the population through mass surveillance, and 99.9% of data on 99.9% of people of interest through targeted surveillance. You thi…

> They either have a backdoor, or have the capability to add a backdoor in the hardware that generates those keys in the first place > That's never been my stance It took you about a day to go from being absolutely sure of a thing, to absolutely sure you've never believed that thing.

The first quote was about them having nearly unlimited power for targeted surveillance and the second was about not having such power for mass surveillance. You keep confusing them.

Just stick to your original claim that I responded to - I addressed it in the second half of my previous comment which you glossed over.

Re: Stop Breaking TLS

#168

Earlier quoted context omitted.

> They either have a backdoor, or have the capability to add a backdoor in the hardware that generates those keys in the first place > That's never been my stance It took you about a day to go from being absolutely sure of a thing, to absolutely sure you've never believed that thing.

The first quote was about them having nearly unlimited power for targeted surveillance and the second was about not having such power for mass surveillance. You keep confusing them. Just stick to your original claim that I responded to - I addressed it in the second half of my previous comment which you glossed over.

There's no "nearly" in your statement. "a backdoor, or have the capability to add a backdoor in the hardware that generates those keys" is the same God powers claim again. If you now want to water it down with enough caveats it's nothing, this reminds me of how people go from "In lab conditions we can do a timing attack on the electronics from a FIDO key" to imagining that outfits like this just routinely bypass FIDO and so it's worthless.

It's very difficult and expensive to attack our encryption technologies, and so it's correspondingly rare. We are, in fact, winning this particular race.

Encryption actually works not because surveillance is now utterly impossible but because it's expensive. How you went from my pointing out that there's no evidence of this mass surveillance to the idea that I'm claiming these outfits don't conduct targeted surveillance at all I cannot imagine.

Re: Stop Breaking TLS

#169

Earlier quoted context omitted.

I think that's a very loose interpretation of Availability in the CIA triad. This looks a lot like using the MITM hammer to crack every nut. If this is an actual concern, why not deny personal devices access to the network? Why not restrict the applications that can run on company devices? Or provide a separate connection for personal devices/browsing/streaming? Why not treat them like people and actually talk to the…

It’s not at all a loose interpretation. Availability: Ensures that information and systems are accessible and operational when needed by authorized users

I would still say that is loose — are connection issues caused by staff using streaming services generally considered to be DoS?

And on balance I'd say losing Integrity is a bad trade off to make here.

Re: Stop Breaking TLS

#170

Earlier quoted context omitted.

The first quote was about them having nearly unlimited power for targeted surveillance and the second was about not having such power for mass surveillance. You keep confusing them. Just stick to your original claim that I responded to - I addressed it in the second half of my previous comment which you glossed over.

There's no "nearly" in your statement. "a backdoor, or have the capability to add a backdoor in the hardware that generates those keys" is the same God powers claim again. If you now want to water it down with enough caveats it's nothing, this reminds me of how people go from "In lab conditions we can do a timing attack on the electronics from a FIDO key" to imagining that outfits like this just routinely bypass FIDO…

> How you went from [...] to the idea that I'm claiming these outfits don't conduct targeted surveillance at all

Again, I didn't. You concluded that the lack of evidence of public CA abuse indicates lack of surveillance, full stop, as if that's the only viable way of conducting surveillance. Here's a reminder:

> It is striking that we don't see that. We reliably see people saying "obviously" the Mossad or the NSA are snooping but they haven't shown any evidence that there's tampering

That's a reasonable observation with an unsupported and faulty conclusion. It doesn't even matter whether you meant mass surveillance (preceding context) or targeted surveillance here because the conclusion is bunk either way. I discussed that earlier but you keep glossing over it in favor of these absurd tangents.

Post reply on HN