Killed by Proxy¶
de Carné de Carnavalet, X., & Mannan, M. (2016). Killed by Proxy: Analyzing Client-end TLS Interception Software. Network and Distributed System Security Symposium.
Cited by¶
1 citation across 1 artifact.
Each citation links to the sentence it supports in the citing article.
Mechanisms¶
- Forward Proxy Server
- Its sharpest failure mode appears when it filters encrypted traffic: to inspect HTTPS content, the proxy must perform TLS interception, decrypting and re-encrypting on the fly, which deliberately breaks the end-to-end guarantee users assume they have.
This sourceCarnavalet and Mannan show that TLS interception terminates client encryption at the proxy and creates a second TLS connection to the server, replacing the original end-to-end channel.
- Its sharpest failure mode appears when it filters encrypted traffic: to inspect HTTPS content, the proxy must perform TLS interception, decrypting and re-encrypting on the fly, which deliberately breaks the end-to-end guarantee users assume they have.
Verification¶
Does it exist? Confirmed. This work's DOI resolves to a registered record, which fixes its identity. That is all it fixes.
Does it back the claim? Not recorded. The single citation of this work carries no recorded support check.
Support is checked per citation rather than per work — the same source can be cited soundly in one article and wrongly in another. Per-citation recording began recently, so a citation with no recorded check is a gap in the record rather than evidence it went unchecked.
See how references were verified.
Registry ID ref:4c9e96b11247 · see in the full table