|
|
|
|
|
by new23d
978 days ago
|
|
Google Chrome v117 turned on TLS Encrypted ClientHello by default (on 27 Sep?) This will impact the effectiveness and accuracy of outbound traffic filtering* - for those who've implemented it (regardless of vendor.) We've written a short blog post on disabling it with PowerShell, Windows Registry and Google Chrome UI for those who may need to roll this out ASAP and regain visibility. (Disclosure: we are a vendor of an outbound filtering solution and this has impacted our customers already.) *for many websites, the domain name visibility during an HTTPS handshake will no longer be available to firewalls/proxies (unless they were terminating.) |
|
Can you prove this is bad? Not trolling, sincerely concerned we're renavigating discussions that date back to when Ethereal became Wireshark and folks got grumpy they'd have to plug a PSK in to look at things -- often because they were looking at things they had no warrant or cause to examine, paired with inept analysts who'd be stymied by something as simple as Asking Jeeves how to plug said password in to view the traffic as if it was clear.