4 ms·
I'm not quite following how having just enough insights about the encrypted data to perform DDOS mitigation would be scarier than having full read- and write ac
by vader1 12y ago
I'm not quite following how having just enough insights about the encrypted data to perform DDOS mitigation would be scarier than having full read- and write access to the cleartext. Thanks for the responses though, and definitely looking forward to those blogs.
- buro9 12y agoYou are implying something fundamental: that the encrypted traffic could be adequately analysed for insight without the need for decryption. Yet to do so would be to defeat SSL itself, or at least to declare it as insufficient to adequately protect secrets. What CloudFlare is doing isn't defeating SSL or any kind of attack on it. They are merely working around some prior limitations on requiring access to an organisation's private key. As a proxy that is charged with DDoS protection (and other types of protection and performance improvements), they are being asked to terminate and work on the unencrypted data to a very strict set of complience by the end organisations, but they need to do this in a way that does not involve possessing or having access to the private key. Their solution works extremely well given the multiple constraints (technological and legal) that they have.
- handsomeransoms 12y ago> You are implying something fundamental: that the encrypted traffic could be adequately analysed for insight without the need for decryption. > Yet to do so would be to defeat SSL itself, or at least to declare it as insufficient to adequately protect secrets. This is possible through HTTPS traffic analysis, see [0] and [1] for starters. Of course, it's much easier for Cloudflare to do analysis for DDoS protection if they have access to plaintext. Whether this means that SSL is, as you say, "insufficient to adequately protect secrets" is an interesting discussion to have. [0] http://arxiv.org/pdf/1403.0297.pdf http://arxiv.org/pdf/1403.0297.pdf [1] http://blog.ioactive.com/2012/02/ssl-traffic-analysis-on-google-maps.html http://blog.ioactive.com/2012/02/ssl-traffic-analysis-on-goo...