Live data from Hacker News

Industry Concerns about TLS 1.3

ietf.org

191–194 of 194 posts

Re: Industry Concerns about TLS 1.3

#191
post #9

Earlier quoted context omitted.

I call it paper security or checklist security. Usually it is about implementing enough to check off a list of requirements from some document. Antivirus installed? Check (Nevermind it is a Linux box and AV loads a dubious proprietary driver in the kernel with a huge attack surface and remote exploit posibility because of how it does updates), such and such EAL-4 operating system intalled? Check, and so on ... So the…

As far I remember, major banks have been rather secure in the last decades, especially compared to the hipster hackers at Yahoo/Dropbox/github/.... So maybe their checklist is worth a look.

You're right, that's fair. I can't remember a large bank was hacked as to where their customer's money was stolen or anything like that. It is usually retailers and such.

Re: Industry Concerns about TLS 1.3

#192
post #182

Earlier quoted context omitted.

mitm surveillance of employee traffic is basically a cornerstone of enterprise security since those networks are designed to be very squishy on the inside. Thankfully Google is turning the assumption that the perimeter needs to extend to your rather vulnerable clients on its head but that will be several years before it's productized enough that middle managers will be convinced to buy it by a VAR over a game of golf…

That's basically putting the cart before the horse. Security is hard. Hard problems are easier when there are fewer of them. It's easier to build one big wall than lots of little ones. Surveillance of employees is a cornerstone of enterprise security because humans are inherently untrustworthy. One part of the solution to this problem is to define a distinction (using golf[+] of all things as an analogy) between the…

Just to be clear I'm referring to monitoring traffic for security threats. Not for things like stealing source code or applying for jobs or whatever BS some employers are paranoid about.

The reason it's a cornerstone is because your clients, especially laptops, are huge gaping attack vectors. They visit other networks and browse the web. Even if they're browsing the web 100% of the time through a web proxy it's not going to catch everything.

And it's for that same reason Google decided to shrink their perimeter. The distinction between their systems and someone else's is still maintained, but they've accepted and embraced the fact that the laptops used by their employees can and will get owned. So instead of acting as a bridge between the internet and internal squishy networks they sit out there with the internet.

But I'm hardly doing the concept justice. In fact I'm probably hurting it more than helping it. If you haven't read it Google discusses the security concepts in a short paper you can get here: http://research.google.com/pubs/pub43231.html

Re: Industry Concerns about TLS 1.3

#193

Earlier quoted context omitted.

Put the cyber-snooping aspect aside for a minute. Where have the banks been? Why didn't this Andrew Kennedy guy (or any other banks) chime in when this was fresh? Why did this only become relevant to them at the last minute? Forgive me, but I have no sympathy for these institutions. If they really cared about Security, they would have dealt with this nonsense a long time ago. You want to excuse the banks because they…

Do not assume that the people who are responsible for monitoring such things (at the big banks) have only their employer's purse in mind. One cannot rule out... Someone's going to get vastly improved security whether they want it or not! Protocols like TLS protect bank customers from fraud. It is the bank's duty first and foremost to protect their every day customers. If Wall Street always comes first banking's prima…

> If Wall Street always comes first banking's primary product will be despair.

This has already come to be :)

Re: Industry Concerns about TLS 1.3

#194
post #148

Earlier quoted context omitted.

I sense the response was somewhat less receptive for subjective reasons. For example, his tone is too formal and sounds bureaucratic. He refuses to state his actual request until the end of a long winded description of his clout and authority. I think people did listen but were turned off before he even got to the point. edit: Oh dear. Just noticed he has a degree in political science and no development background. H…

> For example, his tone is too formal and sounds bureaucratic. He refuses to state his actual request until the end of a long winded description of his clout and authority. I see that as just being a professional adult. He states who he is, which implies why his opinion matters, then he states his opinion. 'Please don't do this kthxbye!!!1!cos(0)!!' is hardly more persuasive.

I see your point, but I think we have to account for the traditional business culture of software developers.

I think most in this culture lean toward informal speech, and toward stating your argument first and mentioning your credentials last, if at all.

I wanted to send him a private message with suggestions, but couldn't be sure it would be taken constructively and not be hurtful.

Post reply on HN