4 ms·
This seems like such an old fashioned way of thinking. Internet access is increasingly a fundamental human right and is needed to interact with most government
by lox 9y ago
This seems like such an old fashioned way of thinking. Internet access is increasingly a fundamental human right and is needed to interact with most government services in first world countries.
I think assuming you can control any packets that pass through a network ends up being a losing proposition. Why not use things like VPNs to ensure that traffic to sensitive internal services is controlled? Failing that, install software on users computers and don’t allow them to use any non-work internet resources.
- closeparen 9y ago>Internet access is increasingly a fundamental human right and is needed to interact with most government services in first world countries. That's all well and good, but you don't need to do it from your desk at a regulated financial institution. >I think assuming you can control any packets that pass through a network ends up being a losing proposition. This is a very strange statement. All security is always a losing proposition. The best anyone can ever hope for is raising the bar of cost and sophistication an attacker will have to surmount to be successful, but you're still very much obligated (legally, and ethically) to do that. If you possess sensitive data, you need to take steps to detect and prevent exfiltration. If you have employees (such as registered broker-dealers) whose conversations with the outside must be monitored and retained under the law, you need to make sure they're using only the properly configured communication channels. >Why not use things like VPNs to ensure that traffic to sensitive internal services is controlled Because TLS interception is about preventing unwanted egress/exfiltration from the (relatively) trusted zone of a corporate network. >Failing that, install software on users computers and don’t allow them to use any non-work internet resources. Installing the corporate CA on managed endpoints is a prerequisite for TLS interception. The problem VPNs solve has nothing to do with this.