2 ms·
If you control the network infrastructure it is possible to inspect the traffic while still allowing https/SSL. https://www.a10networks.com/resources/glossary/s
by kavok 10y ago
If you control the network infrastructure it is possible to inspect the traffic while still allowing https/SSL. https://www.a10networks.com/resources/glossary/ssl-decryption-encryption-and-inspection https://www.a10networks.com/resources/glossary/ssl-decryptio...
- pedrocr 10y agoOnly if you control the endpoints or have a compromised CA. The whole point of TLS is that you can't inspect traffic even if you own all the cables and routers between the two endpoints.
- kavok 10y agoIf I recall correctly all you have to do is deploy a cert on the client machine. The client connects to the machine doing the inspection and then it handles the final request under the real cert. They do this in corporate networks sometimes.
- a-priori 10y agoThe way this works is that the nation state installs a proxy that does a man-in-the-middle attack on the HTTPS traffic. It receives the incoming TLS handshake from the endpoint, and completes it with a certificate rooted in a 'compromised CA'. Then they handshake with the real server, and proxy the traffic. This allows them to intercept the traffic by shunting the plaintext off of the proxy to another system. Of course, it's plainly obvious to you, the endpoint, that this is going on because have to trust that compromised CA on your device to access the site. They'll, of course, helpfully offer instructions about how to do this and require it to be pre-installed on systems. But if there's no other way to access any HTTPS services? Lots of people will do it.