SSL/TLS Components Each specification (SSLV3, TLS 1.2, TLS1.3) is a set of standards - Each standard is made up of lots of different Ciphers-Suites • Example Cipher-Suite names
8
Arrival of TLS 1.3
9
Major Differences in TLS 1.3 • Gone is functionality bloat
10
Old RSA Key Exchange (before PFS)
11
Perfect Forward Secrecy (PFS) 2011, but really 1990 Chuck
12
Multiple Security Devices With SSLV
13
TLS 1.3 Decrypted
14
Simple: Visibility
15
Stages of TLS1.3 Awareness in Middleboxes
16
Sandwich Approach Let's see what can go wrong
17
Connecting whilst honouring client handshake
18
and not honouring client handshake
19
Resigning Without Verification Security Issue - Exposing Clients to Attack
20
Seamless integrations for better security infrastructure
Description:
Explore the intricacies of SSL/TLS and its impact on network security in this 29-minute conference talk by Andy Shepherd from Symantec. Delve into the evolution of encryption protocols, from SSL to TLS 1.3, and understand their components, including cipher suites and key exchange mechanisms. Learn about Perfect Forward Secrecy (PFS) and its significance in modern cryptography. Examine the challenges faced by security devices in dealing with encrypted traffic and the stages of TLS 1.3 awareness in middleboxes. Discover potential security issues in SSL/TLS implementations, such as resigning without verification, and gain insights into seamless integrations for improved security infrastructure. This talk provides valuable knowledge for cybersecurity professionals and network administrators looking to enhance their understanding of encryption protocols and their implications for network visibility and security.
SSL-TLS and Why It Keeps Your Lake Empty - Andy Shepherd, Symantec