Open cardosec

Case FF10AE · Network · L3 Applied

TLS Inspection Trade-offs

Practise as: Explain it · Interview

Interview questionShould an enterprise decrypt TLS at the proxy? Argue both sides.

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Proxy terminates TLS using an internal CA trusted by managed endpoints, inspects, then re-encrypts upstream
  2. Gains: malware and DLP inspection, visibility into C2 over HTTPS
  3. Risks: proxy becomes a high-value target, may weaken upstream validation or ciphers, privacy and legal issues
  4. Breaks certificate pinning and mutual TLS; exempt banking, health and pinned apps via bypass lists
  5. TLS 1.3 mandates forward secrecy and encrypts the certificate, so passive decryption with a server key fails; MITM is required

If the interviewer pushes back

  • Encrypted Client Hello hides SNI. What visibility is left for a network defender?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.