4.9 • 696 Ratings
🗓️ 17 July 2018
⏱️ 8 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Tuesday, July 17, 2018 edition of the Sands and at Storm Center's |
0:06.3 | Stormcast. My name is Johannes Ulrich, and today I'm recording from Washington, D.C. |
0:12.4 | First of all, thanks to everybody who came to our panel today. We got actually, as usual, I have to say, |
0:19.8 | a lot more questions than we were able to answer. |
0:22.8 | So for all of those who were not able to attend, we will answer some of these questions in upcoming diaries. |
0:31.5 | One issue that actually always sort of comes up in this context is also privacy. |
0:37.3 | And we have a new internet draft |
0:40.1 | that tries to protect the privacy of HTTP. |
0:44.7 | Now, why would you need to protect the privacy of HTTP, which is an encrypted protocol? |
0:50.8 | Well, the problem with HTTP right now is that the host name that you're connecting to |
0:56.7 | is still exposed in the clear due to a feature called server name indication. Server name |
1:03.7 | indication tries to solve the problem where you have multiple HTTP websites that are hosted |
1:09.4 | on one IP address. |
1:12.3 | In this case, the server has to know which key to use and which certificate to send back to the request. |
1:19.3 | This is why the server name is exposed in the clear. |
1:24.3 | Pretty much all current web servers and browsers support this feature, given that |
1:30.3 | you typically do have multiple websites hosted on the same IP address. This used to be a problem |
1:37.4 | with HTTP, and it used to be that you needed a specific IP address and port combination |
1:43.6 | for each HTTP host, but thanks |
1:46.6 | to server name indication, this went away at the cost of less privacy. Now, this latest |
1:53.4 | internet draft does leverage DNS in order to bootstrap encryption. The encryption key would |
2:00.3 | be published via DNS. Another interesting |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.