Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Yeah, no. The network is my property and the contract our employees or partners sign establishes terms for using the network.

And on that basis, you're prepared to throw such a tantrum as to hold up completion and adoption of a crucial cornerstone of protection for people who actually need privacy?



So you're ok with a compromised printer leaking your medical records? Or notes used by a police investigator while researching a unsubstantiated or even false accusation leaking thanks to some drive by malware?

Interception of web traffic stops those threats.

Nobody is throwing a tantrum or compromising a cornerstone of security. You don't really understand the full scope of what you are talking about -- the "cornerstone of privacy" you speak of is really placing ultimately trust in every random web service.

TLS and the root trust problems associated with it are bad enough. Preventing users from making choices about who and what they trust makes those problems dramatically worse.


> So you're ok with a compromised printer leaking your medical records?

No, but you stop that by refusing to let the printer talk out of your network at all.

> Or notes used by a police investigator while researching a unsubstantiated or even false accusation leaking thanks to some drive by malware?

That's where on-host monitoring can protect you. It'll also protect you in case that computer can ever connect to any other network.


>No, but you stop that by refusing to let the printer talk out of your network at all.

That's a lost battle, honestly. If you block traffic from the printer to the internet, it starts sending UDP with faked source addresses.

If you deploy a VLAN the printer can fake the VLAN Tags. If you physically seperate the printer from any direct connection to your firewall, the printer can look for anything on the network it can use to bounce traffic from (like a DNS server or a computer accepting ICMP echo requests)

A sufficiently dedicated attacker can and will extract information through covert channels.


Yeah, I mean it really depends on the brass tacks here.

Whatever happens with TLS1.3, obviously the looming idiocy of the CA system is a larger problem. And yes, you're right, trusting random web services (ie, the other endpoint) is often a mistake.

But at the end of the day, the users that need to be served by TLS are the endpoints, not the proxy operators.

(FWIW, I suspect that TLS as we know it will shift fairly radically anyway as distributed applications become more prominent).


All you have to do is block all TLS on your network and you're good to go.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: