3 ms·
Heh, my employer is rolling out Zscaler this year. The limited trial a few months ago was hell for folks using WSL primarily, with Docker images adding an addit
by deergomoo 2y ago
Heh, my employer is rolling out Zscaler this year. The limited trial a few months ago was hell for folks using WSL primarily, with Docker images adding an additional layer of pain.
The people in the trial got very little done until it was decided to pause it, and I do not have high hopes for when it’s tried again. It strikes me as basically running malware in the name of security.
- sieabahlpark 2y ago[dead]
- UltraSane 2y agoI worked at a government agency that used Zscaler to perform TLS MITM inspection. You have to create a tunnel to a Zcaler datacenter and send all your traffic to them encrypted with a certificate they provide so they can decrypt it. Then they encrypt it again and send it on its way. It can detect things that otherwise could not but you are putting a LOT of trust into Zscaler security because anyone who hacks them can see EVERYTHING you are doing. And it is a HUGE waste of processing power and joules. You can create exceptions for URLs and source IPs. I much prefer filtering on the endpoint before TLS encryption.
- rawgabbit 2y agoI knew Zscaler did MITM. But I thought it only inspected hashes or summaries to detect malicious content. I didn’t know it would encrypt again.
- klooney 2y agoThey even do per-service stuff- their big AI feature is that it will detect people pasting social security numbers or other PII into ChatGPT and block it.
- gruez 2y ago>I didn’t know it would encrypt again. "encrypt it again" in this case means establishing a new TLS connection to the original host and forwarding the decrypted contents in this new connection. This is obviously required if the original host only had a https endpoint, and (more importantly) so the traffic isn't exposed on the wider internet.
- bitwize 2y agoYou'd think last year's Clownstrike incident would put the lie to the efficacy of the fucking-for-virginity approach to endpoint security favored by organizations but no. At the enterprise level, security isn't really about security, it's about having an audit trail so bad actors can be caught after the fact.
- daghamm 2y agoYou would be surprised how much of corporate cybersecurity is done like this. It has not in anyway improved sine crowdstrike, on the contrary EDR shenanigans has probably grow 100% since last year. These security companies must have really good salesmen. Or maybe IT departments are always ran by clueless fools, who knows?
- vladvasiliu 2y ago> Or maybe IT departments are always ran by clueless fools, who knows? I think IT has its fair share of clueless fools, but what I've noticed is that when the "security department" is separate, people there tend to have no idea what they're talking about and rely on checklists. Plus, "everybody uses X, that means we're missing out".
- MaKey 2y agoCorporate IT security seems to be mainly about checklists and compliance, not about actual security.
- mrguyorama 2y agoThere's no reason to do anything else. Nobody has gone to jail as of yet for not securing their company, and even "security" companies that get utterly popped still have plentiful business a year later. There is no legal incentive to do good security. There is no market incentive to do good security. Why is it so surprising to people that we have abysmal security?