3 ms·
My experience with browser companies vs. proxy software companies is that the browser vendors give a much bigger shit about end user security.
by hackcasual 10y ago
My experience with browser companies vs. proxy software companies is that the browser vendors give a much bigger shit about end user security.
- andrewflnr 10y agoYou're assuming people on the LAN can upgrade to recent browsers. A lot of them are stuck on Windows XP. I realize that's a "you have bigger problems" type of scenario, but you also have to play the hand you're dealt.
- Laforet 10y agoIf an organisation has a large number of networked computers on Windows XP they are going to have more issues than that - having no SNI support is one.
- omh 10y agoIf you have an SSL intercepting proxy then you don't need SNI support on the clients.
- jusob 10y agoIf this is an explicit proxy, this is true. But with a transparent proxy, SNI would still be needed to know what domain name is going to be requested.
- userbinator 10y agoWith HTTPS, the Host: header, which is precisely what SNI was designed as a use-case for, can be used.
- jusob 10y agoBut you see the Host header after the TLS handshake, after the certificate was sent. The poitn of SNI is to indicate the host header during the TLS handshake so that you get the right certificate. HTTP with the host header is one layer up. Again, this is for transparent proxy where no CONNECT is being sent.