4 ms·
Are there any corporate MITMs that can handle TLS 1.3 regardless of the client executable? It looks like TLS 1.3 will eliminate the capture of encrypted malwar
by DethNinja 4y ago
Are there any corporate MITMs that can handle TLS 1.3 regardless of the client executable?
It looks like TLS 1.3 will eliminate the capture of encrypted malware communications.
I’m assuming that most of the corporations will ban use of TLS 1.3 which is somewhat problematic for the future of such a core protocol.
- mcny 4y agoThis has been argued to death. Previously, on HN: https://news.ycombinator.com/item?id=12641880 https://news.ycombinator.com/item?id=12641880 > You're a bit late to the party. We're metaphorically speaking at the stage of emptying the ash trays and hunting for the not quite empty beer cans. > I agree, this isn't a low margin business either. We are talking about inferior security for all internet users for the sake of Well Fargo's quarterly report. > most of the corporations will ban use of TLS 1.3 literally one employee at one bank Wells Fargo said anything about it, after all was said and done. If the future of TLS depends on these idiots, we are all doomed anyway.
- deleted 4y ago[deleted]
- FreakLegion 4y agoYes, TLS 1.3 decryption is now supported in most of the tooling these companies use. The most widely deployed enterprise firewall for example added it a couple years ago[1]. The linked thread in the other reply to your question is 6 years old and the issues have basically been resolved. 1. https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/decryption/decryption-concepts/tlsv13-ssl-decryption-support https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/d...
- tialaramex 4y agoNote that this (and similar technologies from other vendors) is actually just a proxy. There is no "Man in the middle" in the cryptographic sense, the user has decided (or been forced by corporate policy) to allow their communications to be snooped by the proxy. If you go look at the certificate chains in your browser, you'll see that yup, instead of a public CA you're trusting Palo Alto Networks Inc. or whoever to "verify" that you're really talking to news.ycombinator.com
- deleted 4y ago[deleted]
- FreakLegion 4y agoForward proxy is the most common configuration (and is what most people have in mind when they say "MITM" anyway), but you can also load server certs directly. Depending on the key exchange method there may still be proxying, but it's transparent to the client at that point.
- Thorrez 4y ago>(and is what most people have in mind when they say "MITM" anyway) Forward proxying isn't what I have in mind when I think MITM. Forward proxying means changing your browser settings to format the request in a new way and intentionally send it to a proxy which will then forward it to the destination. MITM means the browser attempts to send it to the destination without any formatting change, but a MITM inserts itself in the middle through some mechanism (modifying DNS, modifying IP routing).
- FreakLegion 4y agoThe context is TLS decryption in enterprise network security. People using MITM here are talking about proxying in a broad sense (the sense tialaramex used), not browser settings. "Forward proxy" is just the name of the setting in the firewall I linked. I think what I said also holds generally, though, e.g. "MITM" is a standard way of describing tools like mitmproxy and Fiddler. These tools of course proxy connections, which is how they're able to work with forward secrecy. Anyway, the actual point of my reply was the "Inbound inspection"[1] decryption option. This option is classic MITM and relevant specifically for the internal traffic use cases mcny linked to. There's still proxying for TLS 1.3, but the client can't tell. 1. https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/decryption/decryption-concepts/ssl-inbound-inspection https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/d...
- Thorrez 4y ago
- tialaramex 4y agoRFC 8446, the TLS 1.3 standard, is almost exactly 4 years old, but in practice some clients and servers spoke TLS 1.3 (either the actual final protocol, or a draft that's equivalent except a parameter is different and the anti-downgrade is disabled in drafts) for many months before that too. Today about half of popular web servers speak TLS 1.3 So, you're describing today's reality as if it's a far off impossible dream that you're sure can't ever happen.
- deleted 4y ago[deleted]