Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Consumer Groups Dig Inside NebuAD Technology » Past BBR stories established Nebuad only monitoring
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Post a:
Post a:
« Copyright violation  
AuthorAll Replies


espaeth
Digital Plumber
Premium,MVM
join:2001-04-21
Minneapolis, MN
·voip.ms
·Vitelity VOIP
·Callcentric
·VoiceStick
·ViaTalk
·Comcast
·Embarq

reply to funchords
Re: Past BBR stories established Nebuad only monitoring

said by funchords See Profile :

The device is inserted in the middle, so it can see the entire transaction, including the cryptographic key exchange.

That said, I have no evidence that it decrypts https, and I personally believe that it would use precious CPU time in a middlebox where processing speed must be an issue.
To be able to decrypt the conversation you need the private key (stored only on the hosting server/load balancer) that matches up with the public key served up in the https negotiation process.

The SSL cert also needs to match up as being issued by one of the default Certificate Authorities that had their authentication keys distributed with the web browser software.

Corporate SSL decoding solutions like that provided by Bluecoat work by having a "special" CA key installed on each of the client machines so that the appliance can spoof the https negotiation of valid Internet sources and have the public SSL key authenticate with the "special" CA that gets installed to the web browser so that the user never sees a pop-up to clue them in to the practice. Where you can notice this is if you look at the SSL cert details itself in the browser you will see that sites like Yahoo would be certified by some mystery CA instead of Verisign/Equifax/GeoTrust/Thawte/etc. The scary thing is that in a corporate environment this key can be distributed very easily/silently through Active Directory.

To be honest, the whole thing creeps me out and I'm usually pretty liberal in my view on acceptable practices in networking.
Forums » Consumer Groups Dig Inside NebuAD Technology« Copyright violation  


Tuesday, 24-Nov 11:42:14 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [95] New AT&T Ad Campaign Hits Back At Verizon
· [67] New Bill Takes Aim At Higher Verizon ETFs
· [30] Earthlink Suffers From Major E-mail Outage
· [30] AT&T Offers New Prepaid Wireless plans
· [27] Frontier Increases Modem Rental Fee
· [15] Vivendi In Way Of Comcast's NBC Desires
· [13] Charter Still Fighting With Creditors
· [10] Senators Want ACTA Made Public
· [10] FCC 'Forgets' There's Limited Competition
· [7] Monday Morning Links
Most people now reading
· Windows 7 boot manager editing questions [Microsoft Help]
· Firearms: Ammo question. [General Questions]
· Big Bank Alternative to Bank of America? [General Questions]
· hawaii in thanksgiving [General Questions]
· CTV & Canwest ask CRTC to order blocking of U.S. programs [TekSavvy]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· What to use while demonoid is down? [Filesharing Software]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· iNum and 911 [VOIP Tech Chat]
· Getting ready to pull the trigger, still have cold feet. [VOIP Tech Chat]