Boston Linux & UNIX was originally founded in 1994 as part of The Boston Computer Society. We meet on the third Wednesday of each month, online, via Jitsi Meet.

BLU Discuss list archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Discuss] Discuss Digest, Vol 88, Issue 10



From: Bill Ricker <bill.n1vux at gmail.com>
>> The downside of this latter approach is that the IT org can then sign
>> certs for *ANY* other site and therefore intercept all HTTPS traffic
>> they wish to see.
>
> If the IT / SEC group is competent to do the one, they're probably already
> doing the other!
>
> (And possibly consider themselves legally required to, to prevent
> exfiltration of sensitive data -- HIPAA, SARBOX, ...)

It's a known thing ... you can buy hardware accelerators that terminate
HTTPS connections from clients and dynamically generate certs for any
host name.

Dale



BLU is a member of BostonUserGroups
BLU is a member of BostonUserGroups
We also thank MIT for the use of their facilities.

Valid HTML 4.01! Valid CSS!



Boston Linux & Unix / webmaster@blu.org