Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Consumer Groups Dig Inside NebuAD Technology » Past BBR stories established Nebuad only monitoring
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Post a:
Post a:
« Copyright violation  

espaeth
Digital Plumber
Premium,MVM
join:2001-04-21
Minneapolis, MN
·voip.ms
·Vitelity VOIP
·Callcentric
·VoiceStick
·ViaTalk
·Comcast
·Embarq

Re: Past BBR stories established Nebuad only monitoring

said by funchords See Profile :

The device is inserted in the middle, so it can see the entire transaction, including the cryptographic key exchange.

That said, I have no evidence that it decrypts https, and I personally believe that it would use precious CPU time in a middlebox where processing speed must be an issue.
To be able to decrypt the conversation you need the private key (stored only on the hosting server/load balancer) that matches up with the public key served up in the https negotiation process.

The SSL cert also needs to match up as being issued by one of the default Certificate Authorities that had their authentication keys distributed with the web browser software.

Corporate SSL decoding solutions like that provided by Bluecoat work by having a "special" CA key installed on each of the client machines so that the appliance can spoof the https negotiation of valid Internet sources and have the public SSL key authenticate with the "special" CA that gets installed to the web browser so that the user never sees a pop-up to clue them in to the practice. Where you can notice this is if you look at the SSL cert details itself in the browser you will see that sites like Yahoo would be certified by some mystery CA instead of Verisign/Equifax/GeoTrust/Thawte/etc. The scary thing is that in a corporate environment this key can be distributed very easily/silently through Active Directory.

To be honest, the whole thing creeps me out and I'm usually pretty liberal in my view on acceptable practices in networking.
Forums » Consumer Groups Dig Inside NebuAD Technology« Copyright violation  


Wednesday, 02-Dec 10:19:01 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [158] Comcast Releasing Promised Usage Meter
· [69] Baltimore To Ban Lazy Cable Installs
· [66] Latest Consumer Reports Survey Not Kind To AT&T
· [60] Broadband Killed The Game Console
· [52] Rogers Unveils The ISP Dream Model
· [45] ACTA: Global Three Strikes
· [41] Rural Carriers Quickly Embracing Fiber
· [35] Charter Exits Chapter 11
· [33] AT&T Top Lobbyist Cicconi Has His Feelings Hurt
· [26] Vivendi Agrees, Comcast/NBC Deal Soon
Most people now reading
· PVP in wow today [World of Warcraft]
· Furnace starts, then shuts off. [Home Repair & Improvement]
· Data Usage Meter Launched [Comcast HSI]
· [WIN7] Outlook express under Windows 7? [Microsoft Help]
· Am I the only one that loves to work in IT? [No, I Will Not Fix Your #@$!! Computer]
· LFM Overkill [World of Warcraft]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· Ooma changing features [VOIP Tech Chat]
· [Newsgroups] Newzleech down? [Filesharing Software]
· So I found a gold mine... [World of Warcraft]