-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 On Wed, 2021-01-06 at 19:18 +0100, Reindl Harald wrote: > the point of https is to clap on dirty fingers of anyone in the > middle > of the connection, no matter if his intention is good or bad My initial thinking was that the https port was just being used, and not that it was actually https traffic, although this seems not to be the case (verifying would require a deeper dive into the packet stream than I have time for right now). > if you can distinct the content of https traffic we have a problem > houston I agree - but it doesn't stop people using port 443 for other data transmission, for example ssh on port 443 often allows you to bypass proxies or overly strict firewalls. Just because it's "reservered" as a port for secure http transmission doesn't mean that's what it's being used for. I suspected it might be sctp traffic, but again I can't verify anything with my current time constraints. - -- Nikolai Lusan <nikolai@xxxxxxxxxxx> -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEVfd4GW6z4nsBxdLo4ZaDRV2VL6QFAl/2EXMACgkQ4ZaDRV2V L6QsWBAAkmb5NgIkNxDqWGM9EAqyd+DvtPADcix4Wq4hdKw1qdW2BJyWq5xgBvCh ty9MzXkkiqeuOL/vr82srZgAIjZJ3Y7gJ2pozanYLEc6celCGHK1J9ElUFvPijF+ z/W/yObxJPUJ5oFHhHr8VBPSF6fmhgKBAgNQaczErrhUyRu8sMElFXun4mRKTbsX RKx4mWFF/lQbQ9p2OMngvJAZRl+Zyxxyu7enFjrzX4IUWhBeznhj/3x3AR4dN7om vhO9gYgQ5uam9/tWURfUhGdBs80DFLrMJMAGoPYfBqLOgzzo6RpBBUyu2A7KtOKx KKlkc2vPBy8mrAQLB0+JvtyY+xU759wp5ItNPAurdt17i6yh6x/UKNLFOUiVeyZE zASBUrw5B/1SwBwtHqiSqlEDiqKU1g7zr+oEbBT8tJot3CT+Kzz+QlqGPa8YykDU Q/mAkTb/kdur4Yil5scpIxBRf+ISCiwZC5gXGo94HkNtHWeLHNWCv/NVLNSbWQb9 5LsGAyXQxA9cmKT78OX4rbGq6iJzZLLKgEi2a0EDAQCy5ZD0y4aGyl91SnHYSmoj 1q9IszexoxC72zqnL7BDpDFSz2RAFoeA7QIrJ5Nq1DxwXw524YOSipqJTrnpeX3/ Trvy610Wf7XA1PtfGfnh2iGC2ETi/Pai/XqWfjlg1ujnROHmwIA= =GHKy -----END PGP SIGNATURE-----