« Caymas: are they or aren't they? Only Kevin McLaughlin knows for sure | Main | Best NAC article I have read in a long time »

March 29, 2007

SSL offloading - when is the end not the end

Michael Farnum has an excellent article up over on ComputerWorld today about SSL offloading.  Michael makes an excellent point that with so many devices decrypting SSL traffic before its intended "end", if that information is then compromised, someone has some 'splaining to do.  A reader comments that he does not consider it to serious a problem, that SSL was to ensure end to end encryption and they just replaced the end.

Reading this article brought back flashes of when McAfee Intruvert first started touting their ability to decrypt and inspect SSL traffic.  They would decrypt at the IPS (often at the gateway) and then send it in the clear to its destination. I thought it was a bad idea then and I think it is a bad idea now.  SSL was intended to encrypt end to end.  When you hijack the end and then send that data in the clear you are defeating the whole purpose of using it in the first place. I understand the need to inspect this traffic, but decrypting this traffic before its "end" is not a acceptable answer for me and is too much of a risk.  Michael is dead on!

SSL offloading / accelerating / load-balancing is scary - Computerworld Blogs

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d83451e4d369e200d835270bb569e2

Listed below are links to weblogs that reference SSL offloading - when is the end not the end:

Comments

My Photo

Subscribe to my blog

Enter your email address:

Delivered by FeedBurner

Lijit Search

Blog Networks

Creative Commons License
This work is licensed under a Creative Commons Attribution-Share Alike 2.5 License.

Search

Lijit Search

Attend a Computer Forensics Boot Camp to better your skills and become a better worker
Blog powered by TypePad
Member since 10/2005