|
|
|
|
|
by enko
4717 days ago
|
|
Hm, I think the HTTPS thing is overblown for sites that are hosted in the US. Almost no large sites do HTTPS termination on the actual app servers; it would be the simplest thing in the world to put the collection device behind the HTTPS endpoint. Why bother trying to piece together data flows over a bunch of disparate backbone networks when you can just hook up a collector at the wellspring? I'd sure they'd be delighted to be able to tick off that whole company as "done", and set the verizon taps etc to ignore anything to them, secure in the knowledge they were getting it all elsewhere. |
|
It's far different for traffic to be plaintext from a load balancer backend, switch, to server interface than over X number of hops.