View on GitHub

Quorten Blog 1

First blog for all Quorten's blog-like writings

What is this network middleware that this ZDnet article talks about? In this case, it is software designed to monitor network traffic by a third party, mainly used by enterprise networks on the premise of monitoring for sensitive information leaks. Unfortunately, currently the only method practiced for doing this with SSL/TLS traffic is to break the encryption entirely, rather than adding a second asymmetric decrpytion key. Often times in the process, the SSL/TLS security level is reduced in the process, increasing the likelihood that a real attacker could compromise a connection.

20181110/https://www.zdnet.com/article/its-2018-and-network-middleware-still-cant-handle-tls-without-breaking-encryption/