If using the "more secure" technology results in more "Entities" intercepting and bumping SSL traffic, then security has been lowered. I'm not saying "how much" it is lowered. It's like open-source If you have specific needs or wants, you are welcome to submit your own work. Your attitude feels a bit demanding -- because you don't like that more people are routinely breaking open SSL streams, you want figures on how much. I'd like to see those too -- so if you want to find out and share the information with us, that'd be great!

In addition to the uptick in those asking how to do SSL bumping (start w/squid-users list and its archives and view the number asking for how to do it, or look at the squid-cache wiki and see the info on how to set it up and note that it wasn't available 10 years ago. People wouldn't take the time to publish how-to's in a wiki if there was no demand. Five-ten years ago, most of the questions were about how to cache various types of content or block it. Now a fair percentage is related to SSL bumping. If you want exact percentages, you are welcome to peruse the archives or google search for those making mistakes with certs.

Dell, for example, installed a root-cert with the private key on all Dell computers that is reinstalled via their update service (https://www.grc.com/sn/sn-535-notes.pdf). Other discussions are going on about whether or not USA certs are trustworthy with the CIA, apparently being caught with more than one suborned root-cert (https://groups.google.com/forum/#!topic/mozilla.dev.security.policy/istISpHpMqE). I've seen articles that talk about companies (including some ISP's) purchasing suborned root-certs for their network/customers.

Since https has become more common, more entities have decided to find ways to intercept and crack that traffic. If you want details as to amounts, you are welcome to contribute... You should feel lucky -- it's not like it is a closed-project where you can't contribute.


In reply to Re^9: SSL on PerlMonks by perl-diddler
in thread SSL on PerlMonks by sapadian

Title:
Use:  <p> text here (a paragraph) </p>
and:  <code> code here </code>
to format your post, it's "PerlMonks-approved HTML":



  • Posts are HTML formatted. Put <p> </p> tags around your paragraphs. Put <code> </code> tags around your code and data!
  • Titles consisting of a single word are discouraged, and in most cases are disallowed outright.
  • Read Where should I post X? if you're not absolutely sure you're posting in the right place.
  • Please read these before you post! —
  • Posts may use any of the Perl Monks Approved HTML tags:
    a, abbr, b, big, blockquote, br, caption, center, col, colgroup, dd, del, details, div, dl, dt, em, font, h1, h2, h3, h4, h5, h6, hr, i, ins, li, ol, p, pre, readmore, small, span, spoiler, strike, strong, sub, summary, sup, table, tbody, td, tfoot, th, thead, tr, tt, u, ul, wbr
  • You may need to use entities for some characters, as follows. (Exception: Within code tags, you can put the characters literally.)
            For:     Use:
    & &amp;
    < &lt;
    > &gt;
    [ &#91;
    ] &#93;
  • Link using PerlMonks shortcuts! What shortcuts can I use for linking?
  • See Writeup Formatting Tips and other pages linked from there for more info.