2 ms·
Being able to look at data inside an SSL tunnel won't tell you if it's communicating your stuff out or not. Only the most obvious leaks are going to be caught t
by 13 12y ago
Being able to look at data inside an SSL tunnel won't tell you if it's communicating your stuff out or not. Only the most obvious leaks are going to be caught that way.
- click170 12y agoDo you realize that you disagree with your first sentence in your second sentence? We understand that only the most obvious leaks will be caught this way. The existence of more sophisticated attackers shouldn't discourage you from trying to catch the less sophisticated ones.
- kyboren 12y agoI hypothesize the most reliably useful information is the metadata concerning each flow itself: what device is on the local end, what IP's on the other end, with what public key and cert chain in the KEX, at what time of day, and how much data is being transferred. If you really want to see the data transferred by a specific app, inspect/modify your app's source code. If you don't have the app's source code, and you are worried about what data it transmits, what are you doing using it?
- 13 12y agoIt's not a contradiction, though it could have been worded better. You're not ever going to be able to tell with certainty that data is not being leaked. As a person with some sensitive files, does it matter how sophisticated the attacker was? The end result is the same either way if they get out.
- Spooky23 12y agoSure it can. Ever heard of DLP? Most leaks aren't terribly complicated.