logoalt Hacker News

zbentleylast Wednesday at 2:03 PM2 repliesview on HN

That’s vastly more failure prone (crowdstrike crashes workstations) and abuse prone (kernel code has the highest privilege level) than processing network traffic at the network/TLS level.


Replies

mirashiilast Wednesday at 2:28 PM

In practice you don't actually need kernel code on a bunch of platforms for this, e.g. NETransparentProxyManager on MacOS. This is not necessarily an endorsement, just worth not mixing in unrelated issues.

iso1631last Wednesday at 5:44 PM

It's also normally deployed by companies who want this level of access anyway

If you don't then you're simply open to encrypted comms over your deep inspection TLS breaking box anyway

show 1 reply