7 ms·
You seem to be conflating enterprise and home/personal networks. They are not the same. > nobody should ever get used to the idea that their network is MITMin
by droitbutch 6y ago
You seem to be conflating enterprise and home/personal networks. They are not the same.
> nobody should ever get used to the idea that their network is MITMing their traffic
and:
> surveillance technologies like this will be abused by people with power over others
Then simply do not add a CA or self-signed cert to your cert store. IOW: the default is secure against SSL MITM. Nothing to "get used to" or "abused".
> What happens when libraries and software starts dropping support for old, insecure protocols, and the new protocols are designed to treat MITM as an attack?
Much simpler than you think. In an Enterprise, they block what they cannot inspect. Clients do not own+run the networks, the enterprise does.
> What happens when they're spending huge amounts of money maintaining forks and patches?
This runs counter to your earlier argument: "You can block spam and outbound attacks without MITMing traffic."
How do you control a myriad of versions of client software on a myriad of versions of devices across a myriad number of applications? There are bound to be some software the Enterprise cannot control (e.g. proprietary, or simply does not have the resources to fix+recompile).
- JoshTriplett 6y ago> Then simply do not add a CA or self-signed cert to your cert store. IOW: the default is secure against SSL MITM. Nothing to "get used to" or "abused". Once upon a time, there were public CAs who would sell you a sub-CA certificate for use on a hardware MITM box, so that you could "transparently" MITM systems on a network without adding a CA. That is now considered unacceptable, and grounds for terminating a CA. What "security" practices in use today will we be saying "once upon a time" about years from now?
- droitbutch 6y ago> What "security" practices in use today will we be saying "once upon a time" about years from now? Can an industry not mature? Previous behavior is not an indicator of the future - and anyone worried about it can contribute to scrutinizing CA's and their guidelines today. Not sure pre-judging current actors based on past actions during a relative nascent industry gets us anywhere - especially since you still haven't provided an alternative solution for enterprises to prevent data breaches or data exfiltration WITHOUT inspection happening somewhere else other than the egress chokepoint.