Spectrum ISP SSL/TLS Interception Bug
andrewgazelka.notion.site
Spectrum ISP SSL/TLS Interception Bug
1–9 of 9 posts
Re: Spectrum ISP SSL/TLS Interception Bug
#2Re: Spectrum ISP SSL/TLS Interception Bug
#3Is it naive of me to ask why it is being just casually accepted that a major ISP is mitm'ing TLS traffic?
ECH and DOH people!
Re: Spectrum ISP SSL/TLS Interception Bug
#4Is it naive of me to ask why it is being just casually accepted that a major ISP is mitm'ing TLS traffic?
They are also probably collecting DNS records from millions of customers too or inspecting SNI on TLS handshakes to know what sites each customer is visiting. ECH and DOH people!
Not sure what TFA means with this, reads like ECH doesn't help
Coincidentally, this article's webpage breaks copy & paste in its tables for presumed reasons of being "cutesy" with table click behavior. Can people please stop doing idiotic shit like this?
Re: Spectrum ISP SSL/TLS Interception Bug
#5Is it naive of me to ask why it is being just casually accepted that a major ISP is mitm'ing TLS traffic?
They are also probably collecting DNS records from millions of customers too or inspecting SNI on TLS handshakes to know what sites each customer is visiting. ECH and DOH people!
Re: Spectrum ISP SSL/TLS Interception Bug
#6Is it naive of me to ask why it is being just casually accepted that a major ISP is mitm'ing TLS traffic?
They are also probably collecting DNS records from millions of customers too or inspecting SNI on TLS handshakes to know what sites each customer is visiting. ECH and DOH people!
My gut tells me the broken intercept is a Nokia product.
Re: Spectrum ISP SSL/TLS Interception Bug
#7During one particularly annoying episode where it effectively became a DOS I had my router log all dropped packets and then rebooted it. Immediately after reconnecting it drops a few incoming martians and invalid packets as if they were still expecting an active connection where there shouldn't have been any. The IPs were mostly upstream endpoints or gateways but at least once it was from a residential IP instead.
Between the weird arbitrary nature of the SSL/TLS handshake issues and the possible spoofing from upstream gateways I get the impression this is much more than just a bug.
Re: Spectrum ISP SSL/TLS Interception Bug
#8Earlier quoted context omitted.
They are also probably collecting DNS records from millions of customers too or inspecting SNI on TLS handshakes to know what sites each customer is visiting. ECH and DOH people!
They most certainly are. Large ISPs use Nokia Deepfield or Kentik for network monitoring, observability and user metrics. Both work due to volumes of metadata from net flows and DNS. My gut tells me the broken intercept is a Nokia product.