4 ms·
You mean American companies like Apple? Whether you trust them or not they've certainly brought it up. Though they might not label the spying indiscriminate; ma
by avdempsey 10y ago
You mean American companies like Apple? Whether you trust them or not they've certainly brought it up. Though they might not label the spying indiscriminate; maybe still 'criminate.
Or are Chinese companies doing some interesting walling-off?
- StavrosK 10y ago(The opposite of indiscriminate is discriminate)
- epicalex 10y agoWoosh
- JshWright 10y agoI don't get it...
- chei0iaV 10y agoReplace the "te" with "l"
- markman 10y agoI'm still lost?
- dpark 10y ago'criminate => criminal The "te with l" tip was for the original "'criminate" and not very clear.
- markman 10y agoDuh I'm sorry I thought that that was an "i". I kept thinking is that some Latin form of pluralizing the word. Oops. Where's my coffee...
- lisper 10y agoIt's a (bad IMHO) attempt at sardonic humor by punning on the word "criminal".
- aniro 10y agoThe root word at play is CRIM See also crime, criminal
- brazzledazzle 10y agoGoogle encrypting traffic flowing between data centers seems to reflect significant awareness of the issue too.
- dlubarov 10y agoWhen I worked at Square we required mutual TLS for almost all service-to-service communication within a datacenter, so sniffing traffic within the datacenter wouldn't be fruitful either (assuming no weakness in the cipher or TLS stack). Is that not common elsewhere?
- granos 10y agoNo. I've had to explain to clients on numerous occasions why I enabled TLS between things in the same data center. Security requires layers and just because the data is on a network you own doesn't mean nobody can get in.
- DyslexicAtheist 10y agothis is a really good point, and there are plenty of articles out there suggesting it's fine to terminate SSL on your app proxy since if you can't trust your own datacenter your security is pants anyway ... These semi-informed claims about security often delivered in set-up instructions are annoyingly frequent too. The attitude seems to be it's fine since everyone does it. I get it why somebody would argue this before but things like letsencrypt make it easy to manage the certificates for your internal hosts. I guess it gets more complex if you have your apps in containers that need their certificates managed etc. Even that shouldn't be this big a deal to make sure renewal is automated with some scripting or even managed properly with a backend CA like r509 ... Also the argument for performance no longer counts when the sales argument could be "we guarantee you e2e encrypted services etc" ... Also Data Engineering jobs become a lot more complicated when suddenly certain data-points are no longer available for visualization on "BI-dashboards" consumed by wann-be tech-savvy CxO's, so that too may be a factor.