Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




firewall-wizards logo Firewall Wizards mailing list archives

Re: Using SSL accelerators in firewalls
From: Carson Gaspar <carson () taltos org>
Date: Mon, 22 Jul 2002 14:21:44 -0400



--On Wednesday, July 17, 2002 10:55 PM +1000 Darren Reed <darrenr () reed wattle id au> wrote:

Let me ask this question another way.

If your bank was using one of these SSL accelerators and it was not
directly attached to the web server, but the "far side" of something
else so they could screen traffic and then pass your data through
some number of other things, unencrypted, would you use that bank's
Internet Banking service which used SSL encryption ?

If you had a choice between that and one which did the SSL encryption
on (or next to) the web server (lets assume all other security measures
are equal), which one would you choose, if you had the chance ?

Are they using IIS? If so, then I'd much rather have non-IIS boxes looking at the plaintext and blocking stupid crap.

--
Carson

_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]