3 ms·
If you have an easy way to do so, you should. Possibly even proxy the traffic via something able to do SSL strip/re-encrypt and monitor that traffic with an ID
by T3OU-736 3y ago
If you have an easy way to do so, you should.
Possibly even proxy the traffic via something able to do SSL strip/re-encrypt and monitor that traffic with an IDS.
- ta1243 3y agoI always make an assumption that people writing nefarious communication will check SSL certificates and thus MITMing it would only work if I can load a root certificate (which typically is only doable on proper devices like phones and laptops, and I don't like the extra risk of having a wide open root that I've generated and have to keep secure on my devices as I don't trust myself enough) However speaking to some people at work who have had experience in the past, seems most malware (and that includes IOT devices) doesn't bother validating certificates or things like ESNI and (validated) DOH, so there's a lot you can find out without breaking TLS, due to the lazineess/incompetence of the malware writers.