Skip to content

Comment on Three Dead Protocolsparent

Comments

I'm actually psyched about Palo Alto's app-id and Snort OpenAppId that maybe firewalls will start allowing things through by behavior instead of port. Then we can have the internet back the way it was designed.

"Looks like TLS". "Also looks like TLS". "That's funny, this one looks like TLS too".

This is very true. That's why you MITM everything with your own CA!

Not necessarily; presumably conservative admins will still configure it to deny-default. Especially if the traffic is encrypted and unfamiliar.

BOFH-admins will configure to accept-and-bitbucket-default; that is, make the other party think it's gotten through, and then ignore everything it has to say.

Maybe throw in some fuzzing: accept-and-respond-with-gibberish-default.

accept-and-spam-MX-record-always

How about accept-and-randomly-lose? I'm a big fan of RFC 748 [1]

[1] https://tools.ietf.org/html/rfc748

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.