aeris22’s avataraeris22’s Twitter Archive—№ 99,171

    1. …in reply to @zauberstuhl
      @zauberstuhl No. You can't proxifying TLS. Never. It's necessary to break CA trust to do that, and so you don't want.
  1. …in reply to @aeris22
    @zauberstuhl And it also require to modify all device on your network to accept the DPI-ing CA certificate. It's not possible, and worse for real malware-able devices in IoT modern world (CCTV, fridge, etc)
    1. …in reply to @aeris22
      @zauberstuhl And also because your device is a gateway, you have to deal with TCP fragmentation (and so adding latency on the network with the packet reassembling needed), one packet alone is meaningless…