Website Security & Threat Management
Monsters in the Middleboxes: Introducing Two New Tools for Detecting HTTPS Interception

Monsters in the Middleboxes: Introducing Two New Tools for Detecting HTTPS Interception

3/18/2019 · Gabbi Fisher, Luke Valenta

What this post added

Introduced MITMEngine, an open-source Golang library for detecting HTTPS interception by comparing TLS Client Hello signatures against known browser and middlebox implementations. Also introduced MALCOLM, a dashboard displaying metrics about observed HTTPS interception on Cloudflare's network. Detailed the mechanics of TLS-terminating forward proxies and reverse proxies, and explained the security implications of HTTPS interception, including weakened security, hindered TLS adoption, and potential for spoofing and data exfiltration.

Read the original post ↗