3 ms·
"A properly configured Palo Alto firewall running SSL Decryption can stop a random user downloading a known zero-day package with Wildfire." Instead that Corp
by fsniper 3y ago
"A properly configured Palo Alto firewall running SSL Decryption can stop a random user downloading a known zero-day package with Wildfire."
Instead that Corp IT should have put a transparently working antivirus/malware scanner on the workstation that would prevent that download to be run at all.
?
DPS/MITM are not security layers but more of privacy nightmares.
- EvanAnderson 3y ago> Instead that Corp IT should have put a transparently working antivirus/malware scanner on the workstation that would prevent that download to be run at all. ? Sure. Then come the complaints that this slows down endpoint devices and has compatibility issues. Somebody gets the idea to do this in the network. Rinse. Repeat.
- fsniper 3y agoOur CorpIT has that and fine tuned it to perfection. No one complains now. So it's possible. Unfortunately they still do MITM which breaks connections regularly.
- EvanAnderson 3y agoIt's a knife's edge. One OS patch, or one vendor change in product roadmap, and you can be right back to endpoint security software performance and compatibility hell. Stuff has gotten better but it's still fraught with peril.
- Bluecobra 3y agoI disagree, I think you should have both as an endpoint scanner (either heuristics or process execution) may not catch anything. (for example a malicious Javascript from an advertisement) Why do you care so much about your privacy while you're on company time using their computers, software, and network? If you don't like it, bring your own phone/tablet/laptop and use cellular data for your personal web browsing. FWIW, it's standard practice to exempt SSL decryption for banking, healthcare, government sites, etc.
- rixed 3y agoNobody complained that they couldn't browse Reddit privately. Everybody was complaining that they couldn't perform their work.