Live data from Hacker News

Industry Concerns about TLS 1.3

ietf.org

41–50 of 194 posts

Re: Industry Concerns about TLS 1.3

#41
post #18

There are a lot of keyboard warriors in this thread. This guy puts forward a rational argument for big business. Unless you have extensive experience in this area, perhaps you shouldn't be so quick to judge "oh they are just spying on their users". The simple answer to this question is that if a way is not given for businesses to decrypt their own traffic that they generated and encrypted, they simply won't encrypt i…

However regulation isn't static. Infact, TLS1.3 is likely to live on longer than any given set of government or industry regulations.

If old regulations have a dependency on TLS1.2, then they'll be stuck on that until they "upgrade"

Re: Industry Concerns about TLS 1.3

#42
post #3

Well, that was kind of a burn. Was the argument by the bankers basically a complaint that retooling would be very expensive? and/or that employee surveillance would be more difficult? (yeah, I'm sure everyone is a fan of that!)

mitm surveillance of employee traffic is basically a cornerstone of enterprise security since those networks are designed to be very squishy on the inside. Thankfully Google is turning the assumption that the perimeter needs to extend to your rather vulnerable clients on its head but that will be several years before it's productized enough that middle managers will be convinced to buy it by a VAR over a game of golf…

Highly culture and jurisdiction dependent. Many places ban this with some narrow exceptions (defense sector etc) in law and/or binding labour org agreements.

Re: Industry Concerns about TLS 1.3

#43
post #35
post #9

Earlier quoted context omitted.

I call it paper security or checklist security. Usually it is about implementing enough to check off a list of requirements from some document. Antivirus installed? Check (Nevermind it is a Linux box and AV loads a dubious proprietary driver in the kernel with a huge attack surface and remote exploit posibility because of how it does updates), such and such EAL-4 operating system intalled? Check, and so on ... So the…

Right. And at the end of the day, skilled attackers can either: a) not care if you decrypt their traffic as they're already in your network and it's too late by the time you're reviewing the incident or b) take a copy of your checklist and say, "well here's something they'll probably never figure out" A little out of the checkbox thinking goes a long way for attackers. It could for enterprises too if they could overc…

Best i can tell, quite a bit of the checklists comes from insurance companies and government regulations.

Meaning that if something hits the fan and the company has their checklists in order, then they can be exempt from liability.

Re: Industry Concerns about TLS 1.3

#44
post #18

There are a lot of keyboard warriors in this thread. This guy puts forward a rational argument for big business. Unless you have extensive experience in this area, perhaps you shouldn't be so quick to judge "oh they are just spying on their users". The simple answer to this question is that if a way is not given for businesses to decrypt their own traffic that they generated and encrypted, they simply won't encrypt i…

Keyboard warrior here - almost any security solution I have heard of honors user installed CA above all else. Not sure about iOS. So decrypting traffic and MITM are still trivially possible on any device the admins have access to.

And MITM is the cornerstone of analysis. It may require spending money, or couple of megabytes more for storage of session keys, but at the end - you have the plaintext on your company devices.

Re: Industry Concerns about TLS 1.3

#45
post #18

There are a lot of keyboard warriors in this thread. This guy puts forward a rational argument for big business. Unless you have extensive experience in this area, perhaps you shouldn't be so quick to judge "oh they are just spying on their users". The simple answer to this question is that if a way is not given for businesses to decrypt their own traffic that they generated and encrypted, they simply won't encrypt i…

With regards to your example, in my experience in the banking industry, you just re-encrypt for the internal leg.

TBH I think the BITS guy is over-egging his case a fair bit.

For all outbound to Internet comms they've got to use an interecepting proxy anyway 'cause they're unlikely to have the relevant private key for the communication. So those systems are in place already.

For inbound comms sure there's a hit, you'd need to decrypt at the time of interception and then re-encrypt with a key you know to avoid storing the data in plaintext, but it's far from impossible. And given that the timeline for deprecation of TLS 1.2 is a loong way off, they've got a load of warning to ensure that they can work around it.

Re: Industry Concerns about TLS 1.3

#46
post #31

Earlier quoted context omitted.

> display a very shallow understanding of how secure systems should work. They still ask about mother's maiden name, prevent paste of passwords, took forever to adopt EMV in the US and other idiocies It's security by cargo-culting

> took forever to adopt EMV in the US and other idiocies Totally agree with your comment, but I'll go a little bit on a tangent here. I am an European, all my cards have always had a chip, I have not even seen a card without a chip until I visited the United States. All this reluctance to adopt chips seems so ridiculous to me. But then I spent more time in the United States and with magnetic stripe cards, and boy do…

nfc: i hold my card up the the screen, a progress bar takes 2 second to light up and i just wait for the transaction to go through. i've had way more issues with failing magnetic strips.

Re: Industry Concerns about TLS 1.3

#47
post #18

There are a lot of keyboard warriors in this thread. This guy puts forward a rational argument for big business. Unless you have extensive experience in this area, perhaps you shouldn't be so quick to judge "oh they are just spying on their users". The simple answer to this question is that if a way is not given for businesses to decrypt their own traffic that they generated and encrypted, they simply won't encrypt i…

> Take this example: A regulation says that all incoming traffic into a banking sector company must be scanned for potential vulnerabilities and exploits, and allows for "compensating controls". If the incoming traffic is unable to be decrypted at TLS1.3, it will simply be decrypted at the boarder of the business and routed internally unencrypted. Sorry, I don't get it. All encrypted traffic is typically decrypted by…

All encrypted traffic is decrypted by the recipient, sure. Who's "the recipient" though? Do all your services handle tls, or do you terminate tls at an haproxy/Nginx/etc before hitting the actual services? How many hops do the unencrypted payloads take inside your network? Do you agree that it would be best to reduce that number to a minimum? There's ways to work around this, but they have trade offs associated with them, and they do have a reasonable requirement here.

Re: Industry Concerns about TLS 1.3

#48
post #18

There are a lot of keyboard warriors in this thread. This guy puts forward a rational argument for big business. Unless you have extensive experience in this area, perhaps you shouldn't be so quick to judge "oh they are just spying on their users". The simple answer to this question is that if a way is not given for businesses to decrypt their own traffic that they generated and encrypted, they simply won't encrypt i…

It isn't so much regulations as boneheadedly conservative internal IT. I've dealt with the same thing in healthcare.

The rest of us shouldn't suffer because it might mean slightly reduced profit margins for these bozos.

Re: Industry Concerns about TLS 1.3

#49
post #31

Earlier quoted context omitted.

> display a very shallow understanding of how secure systems should work. They still ask about mother's maiden name, prevent paste of passwords, took forever to adopt EMV in the US and other idiocies It's security by cargo-culting

> took forever to adopt EMV in the US and other idiocies Totally agree with your comment, but I'll go a little bit on a tangent here. I am an European, all my cards have always had a chip, I have not even seen a card without a chip until I visited the United States. All this reluctance to adopt chips seems so ridiculous to me. But then I spent more time in the United States and with magnetic stripe cards, and boy do…

That has less to do with chip vs stripe, and more to do with how those terminals interface with the POS.

Swiping the stripe at any point during the transaction is tantamount to handing over your card to the cashier and never looking at the bill.

Here is the thing, the stripe holds nothing more than your card number in machine readable form. On the other hand the chip is doing a full on chain of trust review before giving the final ok to the card issuer.

As for not liable, have fun yakking with their lawyers if you ever need to dispute a transaction...

Re: Industry Concerns about TLS 1.3

#50
post #32
post #27

Earlier quoted context omitted.

True enough. But those who steal your account information and use it to pose as you don't follow the rules and regulations.

But the bank follows the regulations that tell it to give me all my money back, if there's some fraud. I don't have any money to lose if the bank does not implement security properly. Only the bank has to lose.

They'll refund you after you've already lost the money, or the attacker might use the bank details as part of larger-scale identity theft that might come to leave you in hot water with law enforcement if he uses your identity to commit a crime. All that inconvenience is your own loss, and the bank paying damages for that doesn't really "fix it"
Post reply on HN