4 ms·
> First, why do you even need HTTPS on a trusted network. PCI compliance among many other regulatory issues. You will be required to show that data is not onl
by pravus 3y ago
> First, why do you even need HTTPS on a trusted network.
PCI compliance among many other regulatory issues. You will be required to show that data is not only encrypted at rest but is encrypted through your entire transport chain regardless of any physical security. The threat model assumes that an attacker is able to temporarily access network resources undetected and can use simple sniffing tools to egress sensitive data. This will not be optional.
- mgaunard 3y agoThat's a whole lot of nonsense. What if you push your data using a custom binary protocol over UDP multicast? Are you suggesting that regulations make it so that everything should be a slow and inefficient https webapp?