3 ms·
That is until Yale than set themselves up to forcefully man in the middle all outgoing https connections.
by dekz 13y ago
That is until Yale than set themselves up to forcefully man in the middle all outgoing https connections.
- jessaustin 13y agoHow can they do that without the cooperation of clients? This won't work in a university the way it works in a corporate environment.
- dekz 13y agoWhy would it not work in a university as it works in a corporate environment?
- milkshakes 13y agoin a corporate environment, you usually have control over the workstations themselves, and can inject your own mitm certificate.
- dekz 13y agoIt doesn't matter whether you control the user environment to covertly install the MITM certificate. You simple notify your network users this is happening with instructions on how to install the certificate. Either the user installs it or not, it's their choice. I am in no way advocating this abhorrent system of 'security'. Simply noting that it is obviously done in the workplaces and in many workplaces. That it can also be done here under 'security' pretences.
- milkshakes 13y ago> It doesn't matter whether you control the user environment to covertly install the MITM certificate. You simple notify your network users this is happening with instructions on how to install the certificate. Respectfully, I disagree. This is certainly possible, but from an operational perspective this would be a nightmare. Even setting aside the likely backlash that would follow in response to such a sweeping policy change, university networks largely consist of diverse, user-managed devices, and supporting a transition through such a change would have a non-trivial cost.
- dekz 13y agoWe are, of course, talking in only hypotheticals. Unfortunately, this is a trend that is becoming more popular in the private business sector on their networks. I cannot foresee a indicator that would prevent this trend crossing over to universities. Individuals at their workplace do also have user managed devices, they also are 'outraged'.
- el_devo 13y agoFor what it's worth, at my university, UNC Chapel Hill, there are two networks, one of which requires you to install a custom root certificate, and is the network that the university prefers you connect to. For devices on which this is not possible, there is another network which only requires that you register your device's MAC address to your university id for access. Regardless of which option you choose, you are required to install another program (unless the OUI of your MAC indicates that it is a device other than a computer) which scans your computer for malware and any software which the university does not allow you to have, such as torrenting applications, and will not allow you to connect to the network until after your machine is cleared. This program must be running the entire time you are connected to the network or you will be disconnected. As a student who works as tech support in the dorms, it certainly is a nightmare!
- jessaustin 13y agoOy. Students at your university certainly have my sympathy. I've always been leery of the mitm cert, not only from the users' perspective, but also from that of the organization. If a rogue administrator used the cert to set up a "real" mitm for a local bank's site, I think the school would be on the hook for that. That's just one example; one could imagine other variations on that theme. Whereas, if the school simply acted as a normal ISP, that whole class of vulnerabilities simply doesn't apply.
- selimthegrim 13y agoI believe Stanford does something similar (as well as forces you to install Sophos bloatware)
- evv 13y agoReally, how?? Wouldn't that require the installation of a custom root certificate on every client?
- nwh 13y agoMy university installed a root CA as part of the signup process for WiFi access. Three of them in fact.
- dekz 13y agoYeah it would. So browers will either get that big red warning or the user can be asked/required to install the certificate to be on the network. It's not a technical limitation but a moral one.
- Nanzikambe 13y agoI'd be really shocked if that's the case, they're essentially sabotaging their own security by exposing a single surface for attack for MITM attacks. Most corporate environments typically do not "proxy" SSL, I know this from experience administrating networks and later abusing this with an SSH tunnel on port 443 allowing me unfettered access. I'd be very interested in technical details on how that's implemented if it is.