Partly in response to the Snowdon revelations, a growing number of organisations around the world are enabling 'perfect forward secrecy' (PFS), F5 Networks' worldwide security evangelist David Holmes told iTWire.
The idea is to protect against the possibility of an agency (not necessarily a government agency, though they are the ones with the budgets required) intercepting and storing HTTPS traffic in the hope that it will one day gain access to the secret key used to encrypt the data.
This could happen if the key was accidentally disclosed, or if a company with legitimate access to it got into financial difficulties and was acquired by the agency, for example.
|
What organisations implementing PFS need to realise, Mr Holmes said, is that it breaks some other security and reliability practices.
Examples include transparent failover to a second data centre in the event of a disaster, or the ability to tap data flows for web analytics aimed at detecting unusual events.
"People should be aware that they have to change things," he warned.
The adoption of PFS is good for F5, Mr Holmes said, as its equipment is widely used to handle SSL encryption and decryption as used in HTTPS, rather than leaving the job to servers.
This approach provides for much simpler key management, and also allows traffic inspection.
Such inspection does mean "you're fooling the user" into thinking that HTTPS provides a secure link from the browser right to the server, but it does address bigger problem: malware getting into systems via HTTPS traffic.
Facebook - not the company itself, but rather the content it delivers - is one of several known sources of malware that can enter an organisation via HTTPS, he said, so there is a need to decrypt and scan such traffic.
Balancing privacy and security can be difficult, but F5's products do allow sophisticated policies. For example, inbound traffic from Facebook can be decrypted and scanned to check for malware, Google search traffic can be decrypted and only examined to see that SafeSearch is on (to avoid NSFW content), while traffic associated with banks and financial institutions is left completely untouched.
So whether an organisation wants to decrypt everything or just to peek into certain pieces of traffic, F5 can help, he said: "that's why we've been so busy."