Hacker News new | past | comments | ask | show | jobs | submit login

Most/all of the traffic would be encrypted.





That wasn't the case in the past. Events over the past 15 years have resulted in most companies encrypting all traffic between datacenters (due to the perceived risk). TLS between consumers and companies is probably at an all time high though due to a push for end-to-end encryption.

TLS doesn't help here, because state actors (including China, Russia) own trusted root certificates, which allow them to TLS-terminate for _any_ website they choose and silently decrypt/MITM the traffic.

TLS offers quite good protection actually: Anytime they create fraudulent certificates they risk burning their CA. Attacks need to be very targeted to keep risk of detection low. Due to Certificate Transparency, hiding attacks got even harder. And for sites that use cert pinning, the attack doesn't even work in the first place.

And eavesdrop is one thing but I'm not clear how you could MITM an undersea cable without the operators noticing.


>and silently decrypt/MITM the traffic.

Except it's not silent because you need to expose your misissued certificate every time. Sure, the average joe won't spot it, but all it takes is one security researcher to expose the whole thing. AFAIK there are also projects by google and the EFF to monitor certificates, so the chances of you getting caught are really high. Combined with the fact that no such attacks has been discovered, makes me think that it probably doesn't occur in practice, or at least is only used against high value targets rather than for dragnet surveillance.


These things get encrypted at a lower layer, macsec. At the transport layer it's all transparent. No need for TLS between your servers, that's just wasted overhead.

You typically encrypt anyway because you just lease the line and buy the b/w. It's operated by a different company and you share the wire with other customers.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: