Re: [fw-wiz] Firewall best practices
- From: Cian Brennan <cian.brennan@xxxxxxxxxxxxxxx>
- Date: Wed, 28 Apr 2010 09:13:46 +0100
On Tue, Apr 27, 2010 at 11:12:40AM -0500, Fetch, Brandon wrote:
Too late:Where it would generate cert errors for every user?
http://files.cloudprivacy.net/ssl-mitm.pdf
And these devices are already in deployment...now, imagine one of these with a wildcard certificate running at a coffee house, or at the aggregation point within a provider's CO POP...
These only make sense where you can install the proxy's wildcard cert on all of
the client machines. Neither coffee houes, nor ISPs can do this.
-----Original Message-----
From: firewall-wizards-bounces@xxxxxxxxxxxxxxxxxxxxx [mailto:firewall-wizards-bounces@xxxxxxxxxxxxxxxxxxxxx] On Behalf Of John Morrison
Sent: Tuesday, April 27, 2010 5:45 AM
To: Firewall Wizards Security Mailing List
Cc: mjr@xxxxxxxxx; Firewall Wizards Security Mailing List
Subject: Re: [fw-wiz] Firewall best practices
My understanding of https (and other PKI-based encryption) is that
only the holder of the private key can decrypt the data encrypted with
the other (public) key in the pair. My view is that the firewall can
only decrypt and inspect https traffic if it is acting as the server
to the external client. It can't intercept and decrypt https traffic
destined for another device - the real server. If it did https would
be worthless. Any hacker could buy such a firewall to sniff and
decrypt all https traffic.
On 23 April 2010 20:18, <david@xxxxxxx> wrote:
On Fri, 23 Apr 2010, Martin Barry wrote:_______________________________________________
$quoted_author = "Marcus J. Ranum" ;
That's why firewalls need to go back to doing what they
originally did, and parsing/analyzying the traffic that
flows through them, rather than "stateful packet
inspection" (which, as far as I can tell, means that
there's a state-table entry saying "I saw SYN!")
Marcus, are you referring to DPI or proxies or both or something else
entirely?
If the firewall doesn't understand the data it's passing,
it's not a firewall, it's a hub.
If an application emulates HTTPS traffic and is proxy aware, how do you
tell
the difference?
There are firewalls on the market that can decrypt HTTPS traffic (and I
believe be configured to block any traffic that they can't decrypt)
David Lang
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
This message is intended only for the person(s) to which it is addressed
and may contain privileged, confidential and/or insider information..
If you have received this communication in error, please notify us
immediately by replying to the message and deleting it from your computer.
Any disclosure, copying, distribution, or the taking of any action concerning
the contents of this message and any attachment(s) by anyone other
than the named recipient(s) is strictly prohibited.
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
--
--
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
- Follow-Ups:
- Re: [fw-wiz] Firewall best practices
- From: Mathew Want
- Re: [fw-wiz] Firewall best practices
- From: Fetch, Brandon
- Re: [fw-wiz] Firewall best practices
- References:
- Re: [fw-wiz] Firewall best practices
- From: Anton Chuvakin
- Re: [fw-wiz] Firewall best practices
- From: Jason Lewis
- Re: [fw-wiz] Firewall best practices
- From: Morty
- Re: [fw-wiz] Firewall best practices
- From: Martin Barry
- Re: [fw-wiz] Firewall best practices
- From: Marcus J. Ranum
- Re: [fw-wiz] Firewall best practices
- From: Martin Barry
- Re: [fw-wiz] Firewall best practices
- From: david
- Re: [fw-wiz] Firewall best practices
- From: John Morrison
- Re: [fw-wiz] Firewall best practices
- From: Fetch, Brandon
- Re: [fw-wiz] Firewall best practices
- Prev by Date: Re: [fw-wiz] Firewall best practices
- Next by Date: Re: [fw-wiz] Firewall best practices
- Previous by thread: Re: [fw-wiz] Firewall best practices
- Next by thread: Re: [fw-wiz] Firewall best practices
- Index(es):
Relevant Pages
|