aeris22’s avataraeris22’s Twitter Archive—№ 99,170

  1. …in reply to @zauberstuhl
    @zauberstuhl No. You can't proxifying TLS. Never. It's necessary to break CA trust to do that, and so you don't want.
    1. …in reply to @aeris22
      @zauberstuhl And it also require to modify all device on your network to accept the DPI-ing CA certificate. It's not possible, and worse for real malware-able devices in IoT modern world (CCTV, fridge, etc)
      1. …in reply to @aeris22
        @zauberstuhl And also because your device is a gateway, you have to deal with TCP fragmentation (and so adding latency on the network with the packet reassembling needed), one packet alone is meaningless…