[tor-talk] SSL Visibility Appliance

2014-12-03 Thread Dedalo Galdos
Last saturday during my Tor Talk in a Security Barcamp someone asked me about this technology which I really don't have much information so I want to share the link in case someone in here has any experience with this. I heard some ISPs are using this in some countries to break into people's ssl

Re: [tor-talk] SSL Visibility Appliance

2014-12-03 Thread Akademika Aka
You need to install the sniffers CA certificate to allow them to break your TLS connections or you need to hack a trusted CA to create some wildcard ones (Comodo incident). Some software like Chrome also uses cert pinning, so only a hardcoded cert is allowed. Afaik Tor uses hardcoded certs for the

Re: [tor-talk] SSL Visibility Appliance

2014-12-03 Thread Dedalo Galdos
Thanks for the answer, I was a little amazed by the demo videos. Regards, Dedalo. 2014-12-03 10:50 GMT-05:00 Akademika Aka akademik...@googlemail.com: You need to install the sniffers CA certificate to allow them to break your TLS connections or you need to hack a trusted CA to create some