3 ms·
You're getting mixed up. DPI on TLS sessions requires a MITM. The problem is (apparently) that there are no enterprise-grade MITM solutions that support TLS 1.3
by zigzigzag 10y ago
You're getting mixed up. DPI on TLS sessions requires a MITM. The problem is (apparently) that there are no enterprise-grade MITM solutions that support TLS 1.3
- kijin 10y agoThat argument is a non-starter. Surely somebody will build and market such solutions once TLS 1.3 becomes widely used. The protocol must be finalized before enterprise-grade products can use it, not the other way around.
- jrockway 10y agoSo here's how I'm imagining the current solution, as implemented at the bank I worked at. Remember first off, there is no route to the Internet from workstations. Everything goes through a regular old HTTP proxy running on a server that accesses both the intra and Inter nets. You send it the host you want ("GET https://example.com/" https://example.com/"), it fetches it and returns the HTML. It is nothing more complicated than: socat tcp-listen:8080,reuseaddr,fork 'system:curl $(grep -m 1 GET | cut -d " " -f 2)' with a little logging to put Nefarious Sites on your Permanent Record.