Re: Firewall best practices

ArkanoiD <[email protected]> Wed, 28 Apr 2010 20:34:05 +0400
Newsgroups gmane.comp.security.firewalls.wizards
Message-ID <[email protected]>
fwtk's grand-child does exactly that: you inspect traffic from "low-security"
sites to treat it just like generic http and leave banking/online payment connections intact.
I am thinking on adding a feature to examine certificates to ensure its validity
without MITMing the SSL itself. Have you seen my paper? I think i posted a link here.

On Tue, Apr 27, 2010 at 03:31:47PM -0400, Marcus J. Ranum wrote:
> 
> In Marcus-land the way we'd do it is have crypto that didn't
> suck, and firewall rules that permitted outgoing crypto only
> to (say, if online banking was an authorized activity during
> office hours) a set of supported sites. Yeah, yeah, I know,
> Marcus-land isn't a real place...
>