oss-sec mailing list archives

Re: On sanctioned MITMs


From: Hanno Böck <hanno () hboeck de>
Date: Fri, 1 May 2015 21:34:05 +0200

My quick take on this:
It is very common that when you run any kind of IT infrastructure that
you outsource some technical parts to third parties. Your security
relies on the question how trustworthy these third parties are.

I don't see anything special here with outsourcing your server's TLS
handling. Or anything special about cloudflare. When you outsource IT
infrastructure you trust someone.

Just a thought experiment that has nothing to do with CDNs or TLS: Most
medium or small Web services don't have their own datacenters. They have
servers - either rented or their own - in a datacenter run by someone
else. With physical access to the machine basically you can own them
completely. There's almost nothing you can do to secure a machine where
non-trustworthy people have physical access.

So I don't deny there are potential problems. But I don't see them as
new or special.


-- 
Hanno Böck
http://hboeck.de/

mail/jabber: hanno () hboeck de
GPG: BBB51E42

Attachment: _bin
Description: OpenPGP digital signature


Current thread: