3 ms·
> An increasing number of businesses are legitimately intercepting encrypted traffic on their networks. It’s pretty much a necessity today. This is blatant FUD
by StudentStuff 7y ago
> An increasing number of businesses are legitimately intercepting encrypted traffic on their networks. It’s pretty much a necessity today.
This is blatant FUD right in the intro, trying to push F5's known bad TLS MITM hardware: https://timtaubert.de/blog/2016/09/tls-version-intolerance/ https://timtaubert.de/blog/2016/09/tls-version-intolerance/
- userbinator 7y agoIt's not black and white. I have a MITM proxy on my network that I use to remove ads, modify pages, and block sites, among other things. In fact, I recommend anyone with "smart"/IoT things on their network to use one, and find out what they're saying... https://news.ycombinator.com/item?id=6759426 https://news.ycombinator.com/item?id=6759426
- jjeaff 7y agoHow do you mitm an iot device? Usually you have to install a ca on the device itself. And most iot devices are not open for that kind of access.
- maxaf 7y agoThere are plenty of “smart” IoT devices that use client-side cert pinning as a defense mechanism against MITM attacks.
- jjeaff 7y agoThey wouldn't even need cert pinning would they? Just cert validation. Unless you have access to the device to install an alternate ca, then regular cert validation is going to fail when it reads your fake cert issued from a non-authoritative source.