Re: [fw-wiz] The Outgoing Traffic Problem --



On 7/12/06, Marcus J. Ranum <mjr@xxxxxxxxx> wrote:
<..>
As far as I can see, the endgame is going to be one of two
things.
- Organizations are going to try to add signature-style
controls to SSL transactions and are going to rely on "man
in the middle" style interception tricks and (call 'em what
you want) signatures to detect malicious traffic
- Organizations are going to have to positively identify
sites with which it is necessary/appropriate to do SSL
transactions

I don't see a lot of future in EITHER of those options. The first
one falls apart really fast if anyone ever fixes SSL's certificate
trust model (not highly likely) but since it's signature-based
it'll fail when the hackers add superencryption to their command
streams. The second option would have worked if it had been
<..>


One branch of the military that I'm working with across the pond, has
recently moved to option 1, specifically using bluecoat SSL proxies to
scan SSL-encrypted traffic. They are also significantly reducing the
(already limited) sites that can be accessed.
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • Re: [fw-wiz] The Outgoing Traffic Problem --
    ... Organizations are going to try to add signature-style ... controls to SSL transactions and are going to rely on "man ... sites with which it is necessary/appropriate to do SSL ... use a sandboxed app that is allowed to do very little indeed. ...
    (Firewall-Wizards)
  • [fw-wiz] The Outgoing Traffic Problem --
    ... about recent hacks against the US State Department ... SSL connectivity. ... Organizations are going to try to add signature-style ... the impact that the spammers have had on Email systems: ...
    (Firewall-Wizards)
  • Re: [fw-wiz] The Outgoing Traffic Problem --
    ... technology to break into computers, and they can use the same technology ... to transmit stolen information covertly off a victim's network. ... No SSL Firewalls!!!!! ... Organizations are going to try to add signature-style ...
    (Firewall-Wizards)