Jump to content

tom_newton

Smoothwall Staff
  • Posts

    5,873
  • Joined

Everything posted by tom_newton

  1. So, TLS1.3 will only cause us issues when 1.2 is no longer available - in that you won't be able to use "peeking" to determie the domain ahead of a decision to MITM. We've always been a client-first mitm though, and used SNI to determine the MITM rules, which should continue to work post 1.3. I will agree that there's a limited shelf life on all technologies - and there's a tug-of-war between individual privacy and the needs of schools and businesses. IMO it would have been sensible to make trusted interception part of the spec - and much easier and more user-obvious, but what do I know
  2. OK, smells filtery for sure - these are definitely traffic patterns we've succeeded in blocking, and I've replied further on t'other thread.
  3. And this is ipad, yes? From our reverse engineering of the Http traffic (which this MUST be, as your firewall ports are blocked), it never responds with a valid HTTPS certificate. Are you seeing any successful connections to psiphon-y domains? (they usually look like 4 dictionary words with a .com, and don't resolve in public DNS)
  4. Yes, blocking bare IPs is a guardian feature - we then won't allow a web connection that isn't to a host via DNS (as in "someone's got a list of IPs from elsewhere). Validating certs does a lot of good - largely because one of Psyphon's tricks is to make an HTTPS CONNECT to sites that have self-signed certs for domains that don't exist. Guardian's cert validation blocks this, so it is an effective part of the defence against psiphon without needing decrypt and inspect.
  5. Be interested to hear what's knocked your confidence - we have certainly had our tribulations over the last few years, but we are coming back from them stronger
  6. Just to keep you up-to-date, our current suggestions are to implement a block-then-allow policy on the firewall (most hosts don't need any open ports) as psiphon uses a wide range of existing ports. In the Guardian policy side, you will need at least "validate certificate" rather than do-not-inspect. This does NOT require your users to install a certificate, so is suitable for BYOD. Also block bare IP addresses. We're currently reverse engineering the latest phsiphon to see if we can work with less restrictive firewall rules.
  7. Our categorization team are working on this and have managed to block it, but you need to decrypt and inspect. We're working with our dpi partners to see if we can do it more efficiently
  8. Should be a fairly small amount of extra load. In fact the handshake is the most expensive part of most ssl connections.
  9. Ssl inspection should not be a problem for performance...
  10. Do you actually see traffic hitting the smoothwall - eg. if you visit 888.com do you see the smoothwall saying "888.com, allowed, 200" in the proxy log? Sounds like the radius auth is working (so you're seeing usernames) but the web traffic isnt actually being filtered. Set the Smoothie as the default gw for these clients, and put transparent proxy on if it's not already.
  11. A solid answer from @admadster there - without certs, or inspection "in browser" you won't be able to see anything in SSL. Also, once you broke it, that's done there's no way to "un-MITM" the stuff you don't want to block (otherwise people could snoop your stuff without you knowing).
  12. FWIW this injection will have been blocked by your Smoothwall content filter - as we will have MITM'd the connection ad spotted the Javascript miner.
  13. VRRP is definitely a nice way to do this - but may be overkill, particularly if this is a tick-in-a-box. Smoothwall's failover will do what you need with no need to do anything "clever" with the DSL connection. You could also then get crafty and use bandwidth management to prioritise certain traffic on the failover line. If you're worried about 1 smoothie as a single point of failure, you can always go for an HA pair.
  14. ISTR making 2 fac work with Duo security years ago - so it may well be possible. What's your preferred 2-fac poison?
  15. My coffee mug - it had been hidden inside the PC by a colleague who had got tired of my habit of leaving my mug on the edge of peoples' desks
  16. It's worth pointing out that the default config does exclude banking sites from decryption. If you could check to see if HSBC is decrypted (you'll get a different cert if you are being MITMd) then you can tell if your county kept this default. If that's the case, and you think a site is missing from that category, please let support know. Or post it here. Political sites - I would have though the act of visiting the site would be sufficient. If you're worried about others finding out about your political leanings i'd avoid using a computer in a filtered environment such as a school or public place to access to those sites at all. As for sites with passwords etc - the Smoothwall doesn't store ay data that passes through, so you have nothing to worry about there.
  17. https://www.mockaroo.com/ might be bent to your will
  18. It's built, but there's been some consternation regarding changing the name of a category (it extends a category we used to use for internal purposes) so it's delayed the release. Should be out real soon now.
  19. Some good points here - i'd love to talk to you in the new year about what's important to you from Smoothwall, and indeed what's not!
  20. As a very long serving Smoothwall employee, and now back in the fold after a couple of years away, I can tell you that there's not been any talk of outsourcing - I wouldn't have come "home" if the new management team were all about cutting costs. When I left, I won't deny I had my frustrations - certainly it had become harder to support the product, and perhaps some of the ways we went about addressing that weren't perfect. It's my belief, and expectation, that by combining functions into one office we will reduce the number of "silos" in the organisation and customers will feel the difference in our ability to react to support issues. The new investment means we will be freer to address issues "at source" and make the product better - this is Smoothwall maturing as a product and a company. Before making my decision to return I spoke with the new CEO, the new Chairman, the interim CTO, and a number of other members of the management team - I think they have a good vision for Smoothwall, and a focus on education, and my role will be to help deliver that vision. I really feel for my colleagues in Fareham who don't want to move to Leeds - it's a hard situation to be in, and one I have been in myself. The development and support team have been impacted, but have the option to stay with us well into 2018 and we hope they will continue to contribute throughout the transition. As for talk of pricing - we believe we offer an excellent value product and service, and we want too improve on that value. I can assure you that other offerings are occasionally cheaper, and occasionally more expensive, I don't think there's a product out there we've never beaten on price, and been beaten by. It's a funny old game, as they say If anyone wants to have a chat with me about this, my old email address should be operational by now, or come and get hold of me at BETT. I look forward to picking up old friendships and building some new ones. Tom
  21. Lastpass Enterprise is OK. The admin console was a bit ninky nonky but they seem to have revamped it of late. It makes sharing passwords much more secure, in situations where you're forced to.
  22. I guess schools do have a choice - Exa, or one of the myriad "no frills" ISPs and a "a-la-carte" approach, which is far from unusual. I'd count Exa's offering as an expansion of choice, rather than a contraction.
  23. 4 jobs in 15 years - that's not a lot...well, 4 companies in 15 years. I'll try and stay in this one a little while...
  24. Glad to be of help. I do miss being in Ed-Tech...
×
×
  • Create New...