Jump to content

Recommended Posts

Posted

Hi All,

 

I experimented with SSL interception a while ago but had lots of issues so continued with filtering based on URL. I have a few questions I was hoping some of you could answer:

 

*Does SSL interception work with sites using HSTS?

 

*Do you add exceptions to sites like internet banking?

 

*What is the HR/Legal view on SSL interception?

 

*Is simply filtering on domains/URL still sufficient for safeguarding needs?

 

 

Thanks,

Posted (edited)

Hi @gsk, answered your questions below - if you've any follow up questions let me know :)

 

*Does SSL interception work with sites using HSTS?

Yes, SSL interception will work for domains which implement HSTS. Similarly, domains which implement HPKP (HTTP Public Key Pinning) will not be adversely affected as any certificate authorities installed by the user will be trusted by the browser.

*Do you add exceptions to sites like internet banking?

 

Absolutely, new Smoothwall customers who choose to use HTTPS Decrypt and Inspect will have the 'Online Banking' category in a 'Do Not Inspect' rule by default - this is recommended by Smoothwall.

*What is the HR/Legal view on SSL interception?

 

Probably not the best person to answer this one but ultimately it will depend on where you are in the world. In the UK the vast majority of schools use HTTPS Decrypt and Inspect to ensure students are protected at all times, in the United States I believe that HTTPS Decrypt and Inspect is not as widely used.

*Is simply filtering on domains/URL still sufficient for safeguarding needs?

 

 

Realistically - no. To best protect your users you should employ a HTTPS Decrypt and Inspect policy if possible, however if your just want to test it out then I recomend taking a look at this article on our knowledge base which goes through the best categories to set up a HTTPS Decrypt and Inspect policy against as a bare minimum for safeguarding.

 

Chris

 

 

Edit - Only just realised that this wasn't posted on the Smoothwall forum - but the above should be correct regardless of who is providing your web filtering.

Edited by CSmith
Posted
Why do people exclude internet banking sites from these kinds of things? Our AUP as I'd imagine most AUPs state that school equipment is for work use only. If people go on their internet banking in school they are violating school policy anyway. Whats the rational behind disabling inspection for these sites?
Posted
Why do people exclude internet banking sites from these kinds of things? Our AUP as I'd imagine most AUPs state that school equipment is for work use only. If people go on their internet banking in school they are violating school policy anyway. Whats the rational behind disabling inspection for these sites?

 

School accounts are also accessible via Internet Banking, which in most places is a requirement. Rather keep traffic like that protected as much as possible.

Posted
Why do people exclude internet banking sites from these kinds of things? Our AUP as I'd imagine most AUPs state that school equipment is for work use only. If people go on their internet banking in school they are violating school policy anyway. Whats the rational behind disabling inspection for these sites?

 

If they aren't meant to access them, block them. I don't have an issue with someone doing some quick banking in a spare few minutes and I don't want any accusations of impropriety. I have also found some APIs get in a flustter if you go through HTTPS decrypt.

Posted
Why do people exclude internet banking sites from these kinds of things? Our AUP as I'd imagine most AUPs state that school equipment is for work use only. If people go on their internet banking in school they are violating school policy anyway. Whats the rational behind disabling inspection for these sites?

 

Finance might use it?

 

We allow personal access to sites such as online banking. Many staff work late / early and I have no issues with them checking their balance. They give something to the schools and we give something back.

Posted
OK, thanks for that so far. Can you implement keyword blocking on google and safesearch enforcement at a network level without SSL Interception?
Posted
OK, thanks for that so far. Can you implement keyword blocking on google and safesearch enforcement at a network level without SSL Interception?

 

Keyword blocking - no, because your web filter won't be able to see the contents of the page without SSL Interception.

Enforcing safe search - yes, Smoothwall provide a content mod that will do this for you ('Enable Google SafeSearch') but if you're not behind a Smoothwall you can follow the instructions under 'Advanced > Turn on SafeSearch VIP' on this Google KB article - https://support.google.com/websearch/answer/186669?hl=en which will force SafeSearch for your entire network.

 

Chris

Posted
I'm probably showing my ignorance here, but can't the firewall see the url you're accessing ie, "https://www.google.co.uk/search?q=naughtywords' and block on that basis?
Posted
Why do people exclude internet banking sites from these kinds of things? Our AUP as I'd imagine most AUPs state that school equipment is for work use only. If people go on their internet banking in school they are violating school policy anyway. Whats the rational behind disabling inspection for these sites?

 

Whether or not to intercept is usually a separate question to whether or not to block.

 

I think most people would say that intercepting banking stuff would be unwise, just because the school could end up storing financial data and may become liable for any money that is lost if their systems were compromised in the future. (I wouldn't like to say whether or not someone breaking the AUP would affect the school's liability in that case).

Posted (edited)
I'm probably showing my ignorance here, but can't the firewall see the url you're accessing ie, "https://www.google.co.uk/search?q=naughtywords' and block on that basis?

 

 

no, if the site has ssl turned on the only thing you can see as a mitm is once google decrypts it on their end they have the full request, and thats why decrypt/inspect is a must on google otherwise google image search becomes a safeguarding minefield

Edited by DGardiner

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...