Re: HTTP/2 and Pervasive Monitoring

> Am 15.08.2014 um 21:41 schrieb Eliot Lear <lear@cisco.com>:
> 
> 
>> On 8/15/14, 7:25 PM, Roland Zink wrote:
>> Don't think that a valid cert really helps here although it may give a
>> hint about who is responsible.
> 
> We don't have causality, but we do have data.  And so one man's
> conjecture is as good as the next's.  Here's mine: the majority of
> illicit servers are actually running on hacked systems and the data is
> being served off a simple HTTP server, where no warning is produced.  It
> costs money to get a cert for that system, which doesn't actually buy
> the miscreant anything.
> 
> Eliot
> 
If the hacked system is a web server then the assumption it will have a valid cert in the future and there will be no need to add one. If the system is at home then my proposal was to stop this in the home users network through inspection of the traffic regardless if a valid cert is installed or not.

Roland

Received on Saturday, 16 August 2014 07:02:24 UTC