3 ms·
Ask HN: How to defend against SSL visibility appliances?
Recently on Tor Talk, there was a discussion of SSL visibility appliances (https://www.bluecoat.com/products/ssl-visibility-appliance). They are able to strip out SSL transparently (good article here: http://www.zdnet.com/how-the-nsa-and-your-boss-can-intercept-and-break-ssl-7000016573/).
Are there any effective means to audit trusted CA's in browsers, so that none of these vendors are in the list? Manually reviewing every CA obviously isn't an option.
Does anyone have any good plugin suggestions, or defensive techniques?
- BCharlie 12y agoI should also mention that I am not asking about defenses in particular applications, such as Tor, which does include hardcoded certs. I am more interested in everyday use while not using specialized services such as VPN clients and Tor.
- TheLoneWolfling 12y agoCertificate pinning helps, although it obviously doesn't prevent an attack against something you haven't seen before.