6 ms·
Any business can look into https traffic, and if you don't have that ability, then you either don't care about half your traffic, or you don't know what you're
by halviti 12y ago
Any business can look into https traffic, and if you don't have that ability, then you either don't care about half your traffic, or you don't know what you're doing/have the proper tools.
Allowing anyone on your network (or your destination's network) to inject whatever they want into your datastream is not an acceptable tradeoff for "I want my job to be easier"
- adricnet 12y agoSide stepping your first point, apologies. The requirements of an individual organization are not something we can always change. There are other technologies to detect and resist injection in communications beside encrypting the whole network, aren't there? Maybe you just need nice HMACs and good crypto of that for that feature. Would that make more sense in your applications? would you trust that more than relying on the OS, or the routers to protect your application / verify the communication source? Thanks for responding and fiercely debating, cheers!