Re: Firewall best practices
ArkanoiD <[email protected]> Wed, 28 Apr 2010 20:34:05 +0400
| Newsgroups | gmane.comp.security.firewalls.wizards |
|---|---|
| Message-ID | <[email protected]> |
fwtk's grand-child does exactly that: you inspect traffic from "low-security" sites to treat it just like generic http and leave banking/online payment connections intact. I am thinking on adding a feature to examine certificates to ensure its validity without MITMing the SSL itself. Have you seen my paper? I think i posted a link here. On Tue, Apr 27, 2010 at 03:31:47PM -0400, Marcus J. Ranum wrote: > > In Marcus-land the way we'd do it is have crypto that didn't > suck, and firewall rules that permitted outgoing crypto only > to (say, if online banking was an authorized activity during > office hours) a set of supported sites. Yeah, yeah, I know, > Marcus-land isn't a real place... >