www.thales-esecurity.com
OPEN
TLS State of the Union
ApacheCon NA 2016
Sander Temme – sctemme@apache.org
2
This document may not be reproduced, modified , adapted, published,
translated, in any way , in whole or in part or disclosed to a third party
without prior written consent of Thales - Thales © 2016 All rights reserved.
OPEN
3
This document may not be reproduced, modified , adapted, published,
translated, in any way , in whole or in part or disclosed to a third party
without prior written consent of Thales - Thales © 2016 All rights reserved.
OPEN
Heartbleed Impact: >60% of sites vulnerable!
4
This document may not be reproduced, modified , adapted, published,
translated, in any way , in whole or in part or disclosed to a third party
without prior written consent of Thales - Thales © 2016 All rights reserved.
OPEN
How Many Eyeballs Are There? Really?
5
This document may not be reproduced, modified , adapted, published,
translated, in any way , in whole or in part or disclosed to a third party
without prior written consent of Thales - Thales © 2016 All rights reserved.
OPEN
The Linux Foundation Steps In
6
This document may not be reproduced, modified , adapted, published,
translated, in any way , in whole or in part or disclosed to a third party
without prior written consent of Thales - Thales © 2016 All rights reserved.
OPEN
The Linux Foundation Steps In
7
This document may not be reproduced, modified , adapted, published,
translated, in any way , in whole or in part or disclosed to a third party
without prior written consent of Thales - Thales © 2016 All rights reserved.
OPEN
Core Infrastructure Initiative Grant for OpenSSL Development
8
This document may not be reproduced, modified , adapted, published,
translated, in any way , in whole or in part or disclosed to a third party
without prior written consent of Thales - Thales © 2016 All rights reserved.
OPEN
So, What Else Happened…
9
This document may not be reproduced, modified , adapted, published,
translated, in any way , in whole or in part or disclosed to a third party
without prior written consent of Thales - Thales © 2016 All rights reserved.
OPEN
So, What Else Happened…
www.thales-esecurity.com
OPEN
What’s Going On Today?
11
This document may not be reproduced, modified , adapted, published,
translated, in any way , in whole or in part or disclosed to a third party
without prior written consent of Thales - Thales © 2016 All rights reserved.
OPEN
Pervasive TLS Deployment
▌ High Traffic Sites now default to TLS
Google, YouTube, Yahoo!, Facebook, Twitter, Netflix (soon), …
▌ Increased consciousness
▌ Increased expertise
Security
Performance (https://istlsfastyet.com)
▌ Going Dark is the new default
Google treats you better when you’re on TLS
12
This document may not be reproduced, modified , adapted, published,
translated, in any way , in whole or in part or disclosed to a third party
without prior written consent of Thales - Thales © 2016 All rights reserved.
OPEN
Go Dark for Free: Let’s Encrypt!
▌ Free, Automated, and Open Certificate tool
▌ Supported by all the browsers
▌ It’s easy!
Run software agent on server
Must have root on host
Creates SSL vhost for Apache httpd
13
This document may not be reproduced, modified , adapted, published,
translated, in any way , in whole or in part or disclosed to a third party
without prior written consent of Thales - Thales © 2016 All rights reserved.
OPEN
The Backdoor Debate
14
This document may not be reproduced, modified , adapted, published,
translated, in any way , in whole or in part or disclosed to a third party
without prior written consent of Thales - Thales © 2016 All rights reserved.
OPEN
The Backdoor Debate
15
This document may not be reproduced, modified , adapted, published,
translated, in any way , in whole or in part or disclosed to a third party
without prior written consent of Thales - Thales © 2016 All rights reserved.
OPEN
16
This document may not be reproduced, modified , adapted, published,
translated, in any way , in whole or in part or disclosed to a third party
without prior written consent of Thales - Thales © 2016 All rights reserved.
OPEN
Certificates Ain’t What They Used to Be
17
This document may not be reproduced, modified , adapted, published,
translated, in any way , in whole or in part or disclosed to a third party
without prior written consent of Thales - Thales © 2016 All rights reserved.
OPEN
Certificates
▌ Don’t use self-signed
It’s never been a good idea
Now even less so
▌ PKI is Hard
Don’t set up your own toy PKI
Do it right or not at all
▌ Buy certs for Intranet sites
From cheap commercial CAs
Problem solved
www.thales-esecurity.com
OPEN
What’s Next?
19
This document may not be reproduced, modified , adapted, published,
translated, in any way , in whole or in part or disclosed to a third party
without prior written consent of Thales - Thales © 2016 All rights reserved.
OPEN
More Patches
▌ Increased OpenSSL Development
▌ Increased Adoption
▌ Increased Scrutiny
▌ Which OpenSSL version?
The one that came with your OS
yum update etc.
▌ OpenSSL release streams
0.9.x is dead, don’t use it
1.0.1t released May 3, 2016
1.0.2h released May 3, 2016
1.1.x is in pre-release
Expect more patches, faster
20
This document may not be reproduced, modified , adapted, published,
translated, in any way , in whole or in part or disclosed to a third party
without prior written consent of Thales - Thales © 2016 All rights reserved.
OPEN
Recommended Key Sizes
▌ Currently (May 2016)
RSA: 2048bit
ECC: 256bit
▌ Hashes: SHA-256
Chrome: certificates with SHA-1 in chain insecure
Root certificates with SHA-1 ok
https://security.googleblog.com/2014/09/gradually-sunsetting-sha-1.html
http://dx.doi.org/10.6028/NIST.SP.800-57pt1r4
21
This document may not be reproduced, modified , adapted, published,
translated, in any way , in whole or in part or disclosed to a third party
without prior written consent of Thales - Thales © 2016 All rights reserved.
OPEN
Transport Layer Security 1.3
▌ Currently in development
https://tlswg.github.io/tls13-spec/
▌ Faster
▌ More secure
22
This document may not be reproduced, modified , adapted, published,
translated, in any way , in whole or in part or disclosed to a third party
without prior written consent of Thales - Thales © 2016 All rights reserved.
OPEN
Server
www.example.com
TLS Static Key Handshake
Root CA
Certificate
Server
Certificate
Client
Here’s a Secret Scooby Snack
Hello!
Hello, it’s me!
Verify
Server
Identity
Derive Session Keys
EncryptedCommunications
NOM NOM
decrypt
NOM
23
This document may not be reproduced, modified , adapted, published,
translated, in any way , in whole or in part or disclosed to a third party
without prior written consent of Thales - Thales © 2016 All rights reserved.
OPEN
Server
www.example.com
Handshake with Forward Secrecy
Root CA
Certificate
Server
Certificate
Client
Hello!
Hello, it’s me!
Verify
Server
Identity
Derive Session Keys
EncryptedCommunications
24
This document may not be reproduced, modified , adapted, published,
translated, in any way , in whole or in part or disclosed to a third party
without prior written consent of Thales - Thales © 2016 All rights reserved.
OPEN
Content Inspection
Interwebs
Inspection/WAF Origin Server(s)
Switch Origin Server(s)
httpd WAF
httpd
httpd
Inspection/WAF
TLS
TLS
Re-encrypt
Port spanning
TLS
25
This document may not be reproduced, modified , adapted, published,
translated, in any way , in whole or in part or disclosed to a third party
without prior written consent of Thales - Thales © 2016 All rights reserved.
OPEN
Content Inspection in a Forward Secrecy World
Interwebs
Application
Delivery
Controller
Origin Server(s)httpd
Inspection/WAF
plaintext
TLS
Re-encrypt
26
This document may not be reproduced, modified , adapted, published,
translated, in any way , in whole or in part or disclosed to a third party
without prior written consent of Thales - Thales © 2016 All rights reserved.
OPEN
27
This document may not be reproduced, modified , adapted, published,
translated, in any way , in whole or in part or disclosed to a third party
without prior written consent of Thales - Thales © 2016 All rights reserved.
OPEN
Strong and Getting Stronger
▌ Deeper understanding of the risks
▌ Improved development
Attention
Funding
▌ Pervasive adoption
28
This document may not be reproduced, modified , adapted, published,
translated, in any way , in whole or in part or disclosed to a third party
without prior written consent of Thales - Thales © 2016 All rights reserved.
OPEN
What Can You Do?
▌ Use the tools well
Don’t make smiley faces
▌ Inform yourself
Much information on the googlewebs
▌ Don’t be a certificate problem
Get rid of SHA-1 based certs
Browser vendors don’t like to show errors to your users but they will
▌ Deploy patchable infrastructure
Better software is just down the road
29
This document may not be reproduced, modified , adapted, published,
translated, in any way , in whole or in part or disclosed to a third party
without prior written consent of Thales - Thales © 2016 All rights reserved.
OPEN
Further Reading
▌ TLS 1.3 RFC in development
https://tlswg.github.io/tls13-spec/
▌ Blogs, Talks, Presentations
https://istlsfastyet.com/
https://blog.twitter.com/2013/forward-secrecy-at-twitter-0
https://blogs.windows.com/msedgedev/2015/11/04/sha-1-deprecation-update/
https://t.co/83UYUE7XZP (Chrome browser SSL related warnings)
http://arstechnica.com/security/2015/04/it-wasnt-easy-but-netflix-will-soon-use-
https-to-secure-video-streams/
https://security.googleblog.com/2014/08/https-as-ranking-signal_6.html
30
This document may not be reproduced, modified , adapted, published,
translated, in any way , in whole or in part or disclosed to a third party
without prior written consent of Thales - Thales © 2016 All rights reserved.
OPEN
Questions and Discussion
▌ http://www.slideshare.net/sctemme
▌ sctemme@apache.org
▌ Follow @keysinthecloud on Twitter

More Related Content

PDF
SSL State of the Union
PPT
Ost ssl lec
PDF
Introduction To The DANE Protocol (DNSSEC)
PDF
ION Santiago - DNSSEC and DANE Based Security for TLS
PDF
Sinn und Unsinn von SSL
PDF
Deploying DNSSEC: what, how and where ?
PDF
HTTPS: All you need to know
PDF
Configuring SSL on NGNINX and less tricky servers
SSL State of the Union
Ost ssl lec
Introduction To The DANE Protocol (DNSSEC)
ION Santiago - DNSSEC and DANE Based Security for TLS
Sinn und Unsinn von SSL
Deploying DNSSEC: what, how and where ?
HTTPS: All you need to know
Configuring SSL on NGNINX and less tricky servers

What's hot (8)

PDF
Why Traditional Web Security Technologies no Longer Suffice to Keep You Safe
PPTX
Segurança da era do ssl everywhere
PDF
HARDENING IN APACHE WEB SERVER
PDF
5 TIPS TO SECURE YOUR VPS AND DEDICATED SERVER
PPTX
Demystfying secure certs
PDF
Security and Privacy on the Web in 2016
PDF
Online passwords – understanding "credential stuffing" cyberattack
PDF
Umbrella for MSPs: Enterprise Grade Malware Protection & Containment
Why Traditional Web Security Technologies no Longer Suffice to Keep You Safe
Segurança da era do ssl everywhere
HARDENING IN APACHE WEB SERVER
5 TIPS TO SECURE YOUR VPS AND DEDICATED SERVER
Demystfying secure certs
Security and Privacy on the Web in 2016
Online passwords – understanding "credential stuffing" cyberattack
Umbrella for MSPs: Enterprise Grade Malware Protection & Containment
Ad

Viewers also liked (20)

PPTX
Thales e-Security corporate presentation
PPTX
Virtual Gov Day - Application Delivery Breakout - Northrop Grumman Informatio...
PDF
Caci 2016 guidance_conference
PDF
Exploration and Sciences Technologies in Thales Alenia Space towards Horizone...
PDF
Mexico trends mx 042116 (003)
PPTX
RBMovil Powered by CHARGE Anywhere: MWC
PPTX
ROTLD DNSSEC Implementation
PPTX
Protecting application delivery without network security blind spots
PPTX
Futurex Secure Key Injection Solution
PPTX
Decision criteria and analysis for hardware-based encryption
PDF
[Application guide] IoT Protocol gateway
PPTX
Cloud payments (HCE): a simpler step with Thales HSMs
PPT
Innovation Solutions
PPTX
Risk Analysis Of Banking Malware Attacks
PPTX
Cloud based payments: the future of mobile payments?
PDF
thales-corporate-presentation 2015
PPTX
Le contrat agile ce n'est pas si simple que ça
PPS
Thales
PPTX
HSM Basic Training
PPTX
Joint Presentation - Part 1: The Future Evolution of E-Banking & Cyber Securi...
Thales e-Security corporate presentation
Virtual Gov Day - Application Delivery Breakout - Northrop Grumman Informatio...
Caci 2016 guidance_conference
Exploration and Sciences Technologies in Thales Alenia Space towards Horizone...
Mexico trends mx 042116 (003)
RBMovil Powered by CHARGE Anywhere: MWC
ROTLD DNSSEC Implementation
Protecting application delivery without network security blind spots
Futurex Secure Key Injection Solution
Decision criteria and analysis for hardware-based encryption
[Application guide] IoT Protocol gateway
Cloud payments (HCE): a simpler step with Thales HSMs
Innovation Solutions
Risk Analysis Of Banking Malware Attacks
Cloud based payments: the future of mobile payments?
thales-corporate-presentation 2015
Le contrat agile ce n'est pas si simple que ça
Thales
HSM Basic Training
Joint Presentation - Part 1: The Future Evolution of E-Banking & Cyber Securi...
Ad

Similar to TLS State of the Union (20)

PPTX
ION Sri Lanka - TLS for Network Operators
PDF
ION Santiago: Lock It Up: TLS for Network Operators
PPTX
[Cluj] Turn SSL ON
PDF
How (un)secure is SSL/TLS?
PDF
Sử dụng TLS đúng cách - Phạm Tùng Dương
PDF
HTTPS, Here and Now
PDF
020618 Why Do we Need HTTPS
PDF
SSL, X.509, HTTPS - How to configure your HTTPS server
PDF
Getting started with HTTPS | LumoSpark webinar
PPTX
[Wroclaw #8] TLS all the things!
PPTX
Creating Secure Web Apps: What Every Developer Needs to Know About HTTPS Today
PPTX
PDF
Webinar SSL English
PDF
Are we security yet
PDF
SSL and TLS Theory and Practice 3rd Edition Rolf Oppliger
PPTX
Certificate pinning in android applications
PDF
#Morecrypto (with tis) - version 2.2
PDF
1086: The SSL Problem and How to Deploy SHA2 Certificates (with Mark Myers)
PDF
SSL: Past, Present and Future
PDF
SSL: Past, Present and Future
ION Sri Lanka - TLS for Network Operators
ION Santiago: Lock It Up: TLS for Network Operators
[Cluj] Turn SSL ON
How (un)secure is SSL/TLS?
Sử dụng TLS đúng cách - Phạm Tùng Dương
HTTPS, Here and Now
020618 Why Do we Need HTTPS
SSL, X.509, HTTPS - How to configure your HTTPS server
Getting started with HTTPS | LumoSpark webinar
[Wroclaw #8] TLS all the things!
Creating Secure Web Apps: What Every Developer Needs to Know About HTTPS Today
Webinar SSL English
Are we security yet
SSL and TLS Theory and Practice 3rd Edition Rolf Oppliger
Certificate pinning in android applications
#Morecrypto (with tis) - version 2.2
1086: The SSL Problem and How to Deploy SHA2 Certificates (with Mark Myers)
SSL: Past, Present and Future
SSL: Past, Present and Future

Recently uploaded (20)

PDF
Architecture types and enterprise applications.pdf
PDF
Consumable AI The What, Why & How for Small Teams.pdf
PDF
Improvisation in detection of pomegranate leaf disease using transfer learni...
PDF
Developing a website for English-speaking practice to English as a foreign la...
PDF
UiPath Agentic Automation session 1: RPA to Agents
PPTX
The various Industrial Revolutions .pptx
PDF
Comparative analysis of machine learning models for fake news detection in so...
PPT
Module 1.ppt Iot fundamentals and Architecture
PDF
Getting started with AI Agents and Multi-Agent Systems
PDF
CloudStack 4.21: First Look Webinar slides
PDF
NewMind AI Weekly Chronicles – August ’25 Week III
PDF
sbt 2.0: go big (Scala Days 2025 edition)
PDF
A proposed approach for plagiarism detection in Myanmar Unicode text
PPTX
Modernising the Digital Integration Hub
PDF
Taming the Chaos: How to Turn Unstructured Data into Decisions
PDF
1 - Historical Antecedents, Social Consideration.pdf
PPTX
GROUP4NURSINGINFORMATICSREPORT-2 PRESENTATION
PDF
Zenith AI: Advanced Artificial Intelligence
PDF
Convolutional neural network based encoder-decoder for efficient real-time ob...
PDF
Credit Without Borders: AI and Financial Inclusion in Bangladesh
Architecture types and enterprise applications.pdf
Consumable AI The What, Why & How for Small Teams.pdf
Improvisation in detection of pomegranate leaf disease using transfer learni...
Developing a website for English-speaking practice to English as a foreign la...
UiPath Agentic Automation session 1: RPA to Agents
The various Industrial Revolutions .pptx
Comparative analysis of machine learning models for fake news detection in so...
Module 1.ppt Iot fundamentals and Architecture
Getting started with AI Agents and Multi-Agent Systems
CloudStack 4.21: First Look Webinar slides
NewMind AI Weekly Chronicles – August ’25 Week III
sbt 2.0: go big (Scala Days 2025 edition)
A proposed approach for plagiarism detection in Myanmar Unicode text
Modernising the Digital Integration Hub
Taming the Chaos: How to Turn Unstructured Data into Decisions
1 - Historical Antecedents, Social Consideration.pdf
GROUP4NURSINGINFORMATICSREPORT-2 PRESENTATION
Zenith AI: Advanced Artificial Intelligence
Convolutional neural network based encoder-decoder for efficient real-time ob...
Credit Without Borders: AI and Financial Inclusion in Bangladesh

TLS State of the Union

  • 1. www.thales-esecurity.com OPEN TLS State of the Union ApacheCon NA 2016 Sander Temme – sctemme@apache.org
  • 2. 2 This document may not be reproduced, modified , adapted, published, translated, in any way , in whole or in part or disclosed to a third party without prior written consent of Thales - Thales © 2016 All rights reserved. OPEN
  • 3. 3 This document may not be reproduced, modified , adapted, published, translated, in any way , in whole or in part or disclosed to a third party without prior written consent of Thales - Thales © 2016 All rights reserved. OPEN Heartbleed Impact: >60% of sites vulnerable!
  • 4. 4 This document may not be reproduced, modified , adapted, published, translated, in any way , in whole or in part or disclosed to a third party without prior written consent of Thales - Thales © 2016 All rights reserved. OPEN How Many Eyeballs Are There? Really?
  • 5. 5 This document may not be reproduced, modified , adapted, published, translated, in any way , in whole or in part or disclosed to a third party without prior written consent of Thales - Thales © 2016 All rights reserved. OPEN The Linux Foundation Steps In
  • 6. 6 This document may not be reproduced, modified , adapted, published, translated, in any way , in whole or in part or disclosed to a third party without prior written consent of Thales - Thales © 2016 All rights reserved. OPEN The Linux Foundation Steps In
  • 7. 7 This document may not be reproduced, modified , adapted, published, translated, in any way , in whole or in part or disclosed to a third party without prior written consent of Thales - Thales © 2016 All rights reserved. OPEN Core Infrastructure Initiative Grant for OpenSSL Development
  • 8. 8 This document may not be reproduced, modified , adapted, published, translated, in any way , in whole or in part or disclosed to a third party without prior written consent of Thales - Thales © 2016 All rights reserved. OPEN So, What Else Happened…
  • 9. 9 This document may not be reproduced, modified , adapted, published, translated, in any way , in whole or in part or disclosed to a third party without prior written consent of Thales - Thales © 2016 All rights reserved. OPEN So, What Else Happened…
  • 11. 11 This document may not be reproduced, modified , adapted, published, translated, in any way , in whole or in part or disclosed to a third party without prior written consent of Thales - Thales © 2016 All rights reserved. OPEN Pervasive TLS Deployment ▌ High Traffic Sites now default to TLS Google, YouTube, Yahoo!, Facebook, Twitter, Netflix (soon), … ▌ Increased consciousness ▌ Increased expertise Security Performance (https://istlsfastyet.com) ▌ Going Dark is the new default Google treats you better when you’re on TLS
  • 12. 12 This document may not be reproduced, modified , adapted, published, translated, in any way , in whole or in part or disclosed to a third party without prior written consent of Thales - Thales © 2016 All rights reserved. OPEN Go Dark for Free: Let’s Encrypt! ▌ Free, Automated, and Open Certificate tool ▌ Supported by all the browsers ▌ It’s easy! Run software agent on server Must have root on host Creates SSL vhost for Apache httpd
  • 13. 13 This document may not be reproduced, modified , adapted, published, translated, in any way , in whole or in part or disclosed to a third party without prior written consent of Thales - Thales © 2016 All rights reserved. OPEN The Backdoor Debate
  • 14. 14 This document may not be reproduced, modified , adapted, published, translated, in any way , in whole or in part or disclosed to a third party without prior written consent of Thales - Thales © 2016 All rights reserved. OPEN The Backdoor Debate
  • 15. 15 This document may not be reproduced, modified , adapted, published, translated, in any way , in whole or in part or disclosed to a third party without prior written consent of Thales - Thales © 2016 All rights reserved. OPEN
  • 16. 16 This document may not be reproduced, modified , adapted, published, translated, in any way , in whole or in part or disclosed to a third party without prior written consent of Thales - Thales © 2016 All rights reserved. OPEN Certificates Ain’t What They Used to Be
  • 17. 17 This document may not be reproduced, modified , adapted, published, translated, in any way , in whole or in part or disclosed to a third party without prior written consent of Thales - Thales © 2016 All rights reserved. OPEN Certificates ▌ Don’t use self-signed It’s never been a good idea Now even less so ▌ PKI is Hard Don’t set up your own toy PKI Do it right or not at all ▌ Buy certs for Intranet sites From cheap commercial CAs Problem solved
  • 19. 19 This document may not be reproduced, modified , adapted, published, translated, in any way , in whole or in part or disclosed to a third party without prior written consent of Thales - Thales © 2016 All rights reserved. OPEN More Patches ▌ Increased OpenSSL Development ▌ Increased Adoption ▌ Increased Scrutiny ▌ Which OpenSSL version? The one that came with your OS yum update etc. ▌ OpenSSL release streams 0.9.x is dead, don’t use it 1.0.1t released May 3, 2016 1.0.2h released May 3, 2016 1.1.x is in pre-release Expect more patches, faster
  • 20. 20 This document may not be reproduced, modified , adapted, published, translated, in any way , in whole or in part or disclosed to a third party without prior written consent of Thales - Thales © 2016 All rights reserved. OPEN Recommended Key Sizes ▌ Currently (May 2016) RSA: 2048bit ECC: 256bit ▌ Hashes: SHA-256 Chrome: certificates with SHA-1 in chain insecure Root certificates with SHA-1 ok https://security.googleblog.com/2014/09/gradually-sunsetting-sha-1.html http://dx.doi.org/10.6028/NIST.SP.800-57pt1r4
  • 21. 21 This document may not be reproduced, modified , adapted, published, translated, in any way , in whole or in part or disclosed to a third party without prior written consent of Thales - Thales © 2016 All rights reserved. OPEN Transport Layer Security 1.3 ▌ Currently in development https://tlswg.github.io/tls13-spec/ ▌ Faster ▌ More secure
  • 22. 22 This document may not be reproduced, modified , adapted, published, translated, in any way , in whole or in part or disclosed to a third party without prior written consent of Thales - Thales © 2016 All rights reserved. OPEN Server www.example.com TLS Static Key Handshake Root CA Certificate Server Certificate Client Here’s a Secret Scooby Snack Hello! Hello, it’s me! Verify Server Identity Derive Session Keys EncryptedCommunications NOM NOM decrypt NOM
  • 23. 23 This document may not be reproduced, modified , adapted, published, translated, in any way , in whole or in part or disclosed to a third party without prior written consent of Thales - Thales © 2016 All rights reserved. OPEN Server www.example.com Handshake with Forward Secrecy Root CA Certificate Server Certificate Client Hello! Hello, it’s me! Verify Server Identity Derive Session Keys EncryptedCommunications
  • 24. 24 This document may not be reproduced, modified , adapted, published, translated, in any way , in whole or in part or disclosed to a third party without prior written consent of Thales - Thales © 2016 All rights reserved. OPEN Content Inspection Interwebs Inspection/WAF Origin Server(s) Switch Origin Server(s) httpd WAF httpd httpd Inspection/WAF TLS TLS Re-encrypt Port spanning TLS
  • 25. 25 This document may not be reproduced, modified , adapted, published, translated, in any way , in whole or in part or disclosed to a third party without prior written consent of Thales - Thales © 2016 All rights reserved. OPEN Content Inspection in a Forward Secrecy World Interwebs Application Delivery Controller Origin Server(s)httpd Inspection/WAF plaintext TLS Re-encrypt
  • 26. 26 This document may not be reproduced, modified , adapted, published, translated, in any way , in whole or in part or disclosed to a third party without prior written consent of Thales - Thales © 2016 All rights reserved. OPEN
  • 27. 27 This document may not be reproduced, modified , adapted, published, translated, in any way , in whole or in part or disclosed to a third party without prior written consent of Thales - Thales © 2016 All rights reserved. OPEN Strong and Getting Stronger ▌ Deeper understanding of the risks ▌ Improved development Attention Funding ▌ Pervasive adoption
  • 28. 28 This document may not be reproduced, modified , adapted, published, translated, in any way , in whole or in part or disclosed to a third party without prior written consent of Thales - Thales © 2016 All rights reserved. OPEN What Can You Do? ▌ Use the tools well Don’t make smiley faces ▌ Inform yourself Much information on the googlewebs ▌ Don’t be a certificate problem Get rid of SHA-1 based certs Browser vendors don’t like to show errors to your users but they will ▌ Deploy patchable infrastructure Better software is just down the road
  • 29. 29 This document may not be reproduced, modified , adapted, published, translated, in any way , in whole or in part or disclosed to a third party without prior written consent of Thales - Thales © 2016 All rights reserved. OPEN Further Reading ▌ TLS 1.3 RFC in development https://tlswg.github.io/tls13-spec/ ▌ Blogs, Talks, Presentations https://istlsfastyet.com/ https://blog.twitter.com/2013/forward-secrecy-at-twitter-0 https://blogs.windows.com/msedgedev/2015/11/04/sha-1-deprecation-update/ https://t.co/83UYUE7XZP (Chrome browser SSL related warnings) http://arstechnica.com/security/2015/04/it-wasnt-easy-but-netflix-will-soon-use- https-to-secure-video-streams/ https://security.googleblog.com/2014/08/https-as-ranking-signal_6.html
  • 30. 30 This document may not be reproduced, modified , adapted, published, translated, in any way , in whole or in part or disclosed to a third party without prior written consent of Thales - Thales © 2016 All rights reserved. OPEN Questions and Discussion ▌ http://www.slideshare.net/sctemme ▌ sctemme@apache.org ▌ Follow @keysinthecloud on Twitter