5 ms·
The guy's rationale may be kind of dubious but it's clearly stated: there aren't any tools that do DPI on TLS 1.3 sessions right now.
by zigzigzag 10y ago
The guy's rationale may be kind of dubious but it's clearly stated: there aren't any tools that do DPI on TLS 1.3 sessions right now.
- jrockway 10y agoYou don't need to do deep packet inspection when you just MITM all the traffic.
- blazespin 10y agoInfrastructure upgrades are required. tls1.3 will be expensive
- vacri 10y agoSo let the CEOs have a year of $40M bonuses instead of $50M bonuses. A small price to pay for better security for the rest of us.
- lisivka 10y agoMITM introduces significant delays, yet another single point of failure, adds significant risk of leakage. Current DPI are passive, so they have no such problems.
- ivan_gammel 10y agoIt's technical problem, that can be solved. Dedicated hardware optimized for MITM, probably.
- anonymousDan 10y agoCould you elaborate a bit on what kind of passive DPI you can usefully do on an encrypted TLS session? Do you mean something like this? https://arxiv.org/pdf/1607.01639v1.pdf https://arxiv.org/pdf/1607.01639v1.pdf
- kijin 10y agoDeliberately weakening encryption also adds significant risk of leakage, this time on a global scale.
- bchociej 10y agoThere are absolutely "bump-in-the-wire" intrusion prevention systems with MITM capability.
- zigzigzag 10y agoYou're getting mixed up. DPI on TLS sessions requires a MITM. The problem is (apparently) that there are no enterprise-grade MITM solutions that support TLS 1.3
- kijin 10y agoThat argument is a non-starter. Surely somebody will build and market such solutions once TLS 1.3 becomes widely used. The protocol must be finalized before enterprise-grade products can use it, not the other way around.
- jrockway 10y agoSo here's how I'm imagining the current solution, as implemented at the bank I worked at. Remember first off, there is no route to the Internet from workstations. Everything goes through a regular old HTTP proxy running on a server that accesses both the intra and Inter nets. You send it the host you want ("GET https://example.com/" https://example.com/"), it fetches it and returns the HTML. It is nothing more complicated than: socat tcp-listen:8080,reuseaddr,fork 'system:curl $(grep -m 1 GET | cut -d " " -f 2)' with a little logging to put Nefarious Sites on your Permanent Record.