Half of Q1's malware traffic observed by Sophos was TLS encrypted, hiding inside legit requests to legit services

Throatwarbler Mangrove

Re: It had to happen

It would be a lot easier to detect nefarious traffic, however, if the traffic were not already encrypted.

We're moving to the point that deep-packet inspection at the edge of the consumer network is going to be a necessity. Basically, each home's router/firewall will also need to act as a Web proxy configured to decrypt and inspect all traffic passing through it to search for malware, as is currently common on enterprise networks. That should be a fun exercise.

