PSA: Your firewall may be preventing you from updating to v9 (Security Nerds)

More and more apps are cert pinning or forcing encryption standards that L7 inspection points just can’t do to scale without spending lots of money. I think it’s time to take zero trust to the host level and forget about L7 devices for anything but your own hosted connections.

I would use sass always on solutions like traps, Sophos, bit9 etc. Then use network level authentication to ensure that only those systems who actively have those running are allowed to connect. I prefer Clearpass myself. Auto remediate or quarantine anything that doesn’t.

There is still a place for passive IPS and secure dns solutions but MITM I don’t think is sustainable.

/r/teslamotors Thread Parent Link - i.redd.it