3 ms·
BIG-IP runs DPI (not as good as Sandvine Active Logic), but it's an authoritarian states best friend. Want to compromise another nation state that runs all thei
by scotho3 1y ago
BIG-IP runs DPI (not as good as Sandvine Active Logic), but it's an authoritarian states best friend. Want to compromise another nation state that runs all their traffic through it? These vulns aren't a bad place to start...
- vel0city 1y agoThis is why I don't understand this strong desire for security auditors to have centralized TLS decryption be important to having some high security stance. You're just creating a massive single point of failure and potentially massively weakening encryption.
- palmotea 1y agoIt seems like its a place were there are some serious tradeoffs. You can choose to have visibility into your network traffic or can choose not to. If you choose yes, you create a single point of failure but have the ability to detect breaches elsewhere; if you choose no, you avoid the single point of failure but make it easier for an attacker to exfiltrate data undetected.
- vel0city 1y agoI'm down for endpoints having to report whatever metrics to whatever servers and have their transactions highly audited. I'm down for their connectivity to be highly locked down. It's important to know what's happening on your systems and where data is flowing, I agree! But in the end of I want Alice to talk to Bob and know they and only them are talking I'd like to guarantee that. Instead companies are spending tons of money and work hours doing Eve's work for her, installing her tools and getting it all nicely configured for when she logs in. How many times do we have to backdoor our crypto systems to realize we're not building doors for just us but for everyone else as well?
- toast0 1y ago> You're just creating a massive single point of failure and potentially massively weakening encryption. It need not be a single point of failure. You can set these things up with redundancy. There's certainly an element of adding risk, your interception box is a big target to do unauthorized interception or tampering; but there's also an element of reducing risk --- you'd be potentially able to see and respond to traffic that would be opaque otherwise.
- vel0city 1y ago> You can set these things up with redundancy Yes, so instead of one box with the keys to decrypt all the traffic flowing through the network I'll have multiple boxes that have the ability to decrypt all the traffic. Multiple machines to update and secure and guard against those getting attacked or else everything gets broken.
- mpyne 1y agoPerhaps more importantly to a non-U.S. nations is that there are a lot of military networks that touch the public Internet whose security from outside attack is more or less premised on F5's implementation of mutual TLS to CACs. Finding a way to subvert that authentication or, better yet, bypass it entirely, could put U.S. military networks that can be reached over the public Internet at risk of remote exploitation. Those networks can often also reach other military networks not directly exposed to the public Internet.
- wbl 1y agoThe same F5 responsible for the existence of the padding extension in TLS? And that still has predictable TCP sequence numbers by default.
- tyingq 1y agoThey also provide things that are a juicy target for regular run of the mill hackers. Like centralized services to turn credit card info into tokens, while holding the actual data.