Hacker News new | ask | show | jobs
by hueving 3839 days ago
Very few places follow that threat model. The cost of encrypting between the web tier and the db tier (even from a management perspective) is more than most organizations are willing to pay.

Your threat model is also missing the fact that a network can mitm your connections and also silently duplicate sensitive traffic.

1 comments

Well, no, not if it's SSL across the router. Only if it's terminating there or earlier.