4 ms·
Imho, clients like browsers should just indicate to the user whether their traffic can be intercepted or not (fully encrypted including client hello). And thos
by silverwind 1y ago
Imho, clients like browsers should just indicate to the user whether their traffic can be intercepted or not (fully encrypted including client hello).
And those clients should offer an option to downgrade the TLS connection to make traffic interceptable.
- thyristan 1y agoYou can always manipulate your client into making a connection interceptable by installing your own trusted root CA that can then do MitM. That possibility has always been there and didn't go away with TLS1.3. It's just that many are too lazy to take control of their clients like that. Or they want to do surveillance on clients that aren't theirs to control.
- FuriouslyAdrift 1y agoCertificate pinning has made this very difficult/impossible. We are currently failing legal compliance audits at my work due to this and are having to move cloud things (legal,financial, customer NDA'd data, etc.) back to on-premise because if it. Our cloud HR and payroll systems are really having a tough time staying compliant as the data crosses compliance domains.
- thyristan 1y agoAgreed, didn't think of pinning. That does of course make it very difficult. However, compliance-wise, I'm of the opinion that anything cloud is a bad idea in general. It will just take some time for the bean-counters to realize (if ever).
- immibis 1y ago> And those clients should offer an option to downgrade the TLS connection to make traffic interceptable. They do, it's called http:// http:// and the other option is installing a root cert, of course.
- FuriouslyAdrift 1y agoHSTS is closing this gap, too...