Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think this request is pretty unreasonable, and anything that stops the ability to passively snooping on TLS is a great thing.

I think there could be a security gain though in adding support for a better way to actively MITM TLS traffic though - in having a proper mechanism for filtering proxy firewalls. For some applications (say, school networks) it is OK to monitor and filter traffic, but the way it is done now is terrible for security. Usually this is by terminating the TLS at the proxy, scanning it, and then re-encrypting it with an certificate automatically generated and trusted by an internal CA (whose root certificate is installed on the machines).

The huge problem is that now everyone has to trust all the root CAs installed on the firewall, instead of being able to decide which ones to trust themselves. The firewall has to also decide whether or not to trust self-signed certificates.

Much better would be to be able to decrypt, re-encrypt with a certificate issued by a real CA, and then also send the original certificate along with the handshake. Then, the first time you visited a TLS site, it could pop up a big warning saying 'This traffic is intercepted by firewall.institution.edu, do you consent?' and have a little exclamation mark in the toolbar to always indicate that it's being intercepted. The browser would have to trust both the interception certificate (which encrypts between the firewall and the endpoint inside the internal network) as well as getting the original certificate and deciding whether to trust that (which you don't get now).



Why do you think it's ok to spy on your users on a school network?


The students didn't buy the computers. I did.

Edit: And before anyone starts with the "you shouldn't spy on your users" bullshit: Bollocks. If you want that, welcome to laa laa fantasy land where we all breathe sand.

You will use computers or networks in which the operator is recording everything you do. You can either work within that assumption, or you can stick your fingers in your ears and pretend.

And no, I don't use my employer's[+] computer for anything personally-sensitive and I don't install their shite on mine in order to access their network and when I do use their computer I expect they will watch everything I do even if they don't because I'm using their equipment. I do my real work on my own computer or I don't do my work. The employer is well within its rights to suck on it.

[+] There is no reason why the same should not apply to schools, libraries or any other institution in which people are permitted to use items owned or services controlled by others.


Just to note - I'm referring to schools as in K-12 kind of schools, in my country we don't call higher education 'school'.

This is talking about providing internet for educational purposes to minors. I don't really think there is any argument to say that they should not be subject to automated filtering of the content that they can use on those computers.

Even at work it's probably fair enough. An employer is well within their rights to filter the internet they provide - if you want to do private personal stuff, bring your own laptop and use an LTE dongle or tether it to your phone's internet...


I like your proposed (user-visible) solution quite a lot, this would be great.

I predict certain folks would respond to this by trapping themselves in the indefensible position of "but if they know we're intercepting them, how will we catch them being bad?!?!"




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: