6 ms·
This has nothing to do with security and more with ineffective practices based on security where nobody knows why its done just that its done. Running MitM on c
by blkhawk 3y ago
This has nothing to do with security and more with ineffective practices based on security where nobody knows why its done just that its done. Running MitM on connections basically breaks basic security mechanism for some ineffective security theater. This is basically "90-day password change" 2.0.
- Spivak 3y ago> where nobody knows why its done just that its done Compliance. You think your IT dept wants to deploy this crap? How ever painful you think it is as an end user multiply it having to support hundreds/thousands of endpoints. Look, I hate traffic inspection as much as the next person but this is for security, it's just not for the security you want it to be. This is so you have an audit trail of data exfiltration and there's no way around it. You need the plaintext to do this and the whole network stack is built around making this a huge giant pain in the ass. This is one situation where soulless enterprises and users should actually be aligned. Having the ability in your OS to inspect the plaintext traffic of all incoming and outgoing traffic by forcing apps off raw sockets would be a massive win. People. seem to understand how getting the plaintext for DNS requests is beneficial to the user but not HTTP for some reason. Be happy your setup is at least opportunistic and not "block any traffic we can't get the plaintext for."
- steve_taylor 3y ago> You think your IT dept wants to deploy this crap? Yes, they do.
- bigstrat2003 3y agoNo, they really really don't. Source: I've worked in corporate IT for many years, and this kind of shit is always forced upon us just as much as it is on you guys. We hate it too.
- betaby 3y agoCompliance with exactly what? Their own rules?
- antod 3y agoNot the OP, but currently I work in a regulated industry (financial) where Corporate Risk and Legal depts ask for this stuff (and much more) to satisfy external auditors. The IT people hate it just as much. I had never experienced just how much power a single dept could hold until we got acquired by a large finance enterprise and had to interact with the Risk dept.
- betaby 3y agoStill, what exactly has changed in the last year that Zscaller/Netskope became prevalent? What law has changed? Can someone pinpoint on it. I work for telecom company for example, two years ago there was no zscaller/netskope MITM in my request from the corporate laptop to Internet, today there is one. What law has changed if any what mandates that? If that matter ISP is registered at NJ.
- antod 3y agoNot in your country, but my point about compliance wasn't that a law requires it specifically (laws don't specify technical "solutions" anyway) - just that often the IT dept is compelled by other depts (eg Risk) to implement and support stuff that allows that other dept to show auditors that they are doing something rather than being negligent.
- calgoo 3y ago20 years ago I was configuring VPNs on work laptops that then had all the exit traffic routed to a Bluecoat system to MITM the traffic. The difference is that zScaler is "Zero Trust" so you are actually not on a VPN anymore. It's intercepting the traffic locally and then determining what to do with it. At my current workplace we are using it to access internal services only; allowing all external traffic to exit directly.
- Bluecobra 3y agoMitM can absolutely stop threats if done correctly. A properly configured Palo Alto firewall running SSL Decryption can stop a random user downloading a known zero-day package with Wildfire. Not saying MitM is an end all be all, but IMHO the more security layers you have the better. At the end of the day, it's not your network/computer. There's always going to be some unsavvy user duped into something. If you don't like corporate IT, you're free to become a contractor and work at home.
- fsniper 3y ago"A properly configured Palo Alto firewall running SSL Decryption can stop a random user downloading a known zero-day package with Wildfire." Instead that Corp IT should have put a transparently working antivirus/malware scanner on the workstation that would prevent that download to be run at all. ? DPS/MITM are not security layers but more of privacy nightmares.
- EvanAnderson 3y ago> Instead that Corp IT should have put a transparently working antivirus/malware scanner on the workstation that would prevent that download to be run at all. ? Sure. Then come the complaints that this slows down endpoint devices and has compatibility issues. Somebody gets the idea to do this in the network. Rinse. Repeat.
- fsniper 3y agoOur CorpIT has that and fine tuned it to perfection. No one complains now. So it's possible. Unfortunately they still do MITM which breaks connections regularly.
- EvanAnderson 3y agoIt's a knife's edge. One OS patch, or one vendor change in product roadmap, and you can be right back to endpoint security software performance and compatibility hell. Stuff has gotten better but it's still fraught with peril.