4 ms·
i used to work, 15 years ago, on a (permissive, not covert) monitoring service for a UK national public service, the NHS spine core. We used switches to mirror
by NGRhodes 8mo ago
i used to work, 15 years ago, on a (permissive, not covert) monitoring service for a UK national public service, the NHS spine core. We used switches to mirror ports and capture traffic in promisciouse mode on a few dozen servers
split across a few datacentres that all the traffic went througg. We had certs installed to decode https. We could get enough hardware to do this step easily, but fast enough storage was an issue, we had 1 petabyte of usable storage across all sitesn that could hold a few days of content. We aimed to get this data filtered and forwarded into our central Splunk (seperate storage) and also into our bespoke dashboards within 60s. We often lagged...
- iso1631 8mo agoYou can only decode those https certificates if you are mitming them (and have a compromised certificate) A copy of the certificate and private keys won't help thanks to the magic of Diffie–Hellman, you can't passively (assuming you haven't got a practical quantum computer) read the stream Your company will have deployed root certificates to devices and run as a MITM. This is standard corporate firewall behaviour.
- GoblinSlayer 8mo agoIt's also possible to generate ephemeral keys deterministically, e.g. key=hash(escrow, sslrandom).