Quote from: michmoor on March 26, 2025, 06:32:56 PMQuote from: Patrick M. Hausen on March 26, 2025, 04:40:06 AM"Enumerating badness" does not scale.
I love the way you put that :)
Unfortunately, creating block lists and adding signatures is a security-in-depth "thing" that is good to do—perhaps best practice is to do this additionally.
Breaking TLS is a bad idea but its done. Its one way(not the best way) to stop exfiltration and detect bad payloads that are encrypted.