Application Security and Permissions
Enforcing encryption at scale

Enforcing encryption at scale

7/12/2021 · Neel Goyal, Ajanthan Asogamoorthy, Mingtao Yang

What this post added

This post details the design and implementation of SSLWall, a system developed to enforce transit encryption policies across Meta's network. It leverages eBPF, kprobes, and tc-bpf to inspect and block non-SSL connections at the kernel level without application modifications. The post also introduces Transparent TLS (TTLS) to handle edge cases and legacy applications, using eBPF to redirect connections to a local proxy. Key technical challenges and design decisions, including handling TCP Fast Open and BPF program size limits, are discussed.

Read the original post ↗