Skip to main content

You are not logged in. Your edit will be placed in a queue until it is peer reviewed.

We welcome edits that make the post easier to understand and more valuable for readers. Because community members review edits, please try to make the post substantially better than how you found it, for example, by fixing grammar or adding additional resources and hyperlinks.

Required fields*

7
  • 2
    "I plan on using symmetric encryption" Why? TLS uses symmetric encryption after the requisite handshakes are complete. Rolling your own security is like the 'House of the Rising Sun': it's been the ruin of many a poor boy. Commented Oct 17 at 21:07
  • @JimmyJames because the decision is made above me, it's sadly that simple. I might sway it towards a 3rd party provider, this question is a preparation for the worst-case. Commented Oct 20 at 8:32
  • 1
    @JimmyJames, some goverments mandate use of national CA, making TLS with dynamic certificate verification moot and void. Others ban TLS 1.3, because destination ecryption breaks censorship. Commented Oct 20 at 8:56
  • @Basilevs You can always prune your trust to the CAs you wish to deal with. I've been working with a non-public CAs using TLS for more than a decade. Commented Oct 20 at 14:08
  • @JimmyJames not when you go to jail when some of you traffic can't be MitM decrypted (not that I know of concrete examples, but the ban on VPNs and TLS 1.3 shows clear trend). BTW, publishing VPN configuration instructions are a punishable offense now. Commented Oct 20 at 18:59