Elektrine
EN
Log in Register
Paige Chat Timeline Gallery Friends Lists Email Drive DNS Resolver Domains VPN Kairo Nerve
Remote

Soner Tari

@sonertari@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Open-Source Cybersecurity Developer & Maintainer (since 2006), creating and evolving network defense tools like SSLproxy and UTMFW (formerly ComixWall)

0 Followers
0 Following
4 Posts
Joined May 27, 2025
ComixWall:
https://sites.google.com/site/comixwall
GitHub:
https://github.com/sonertari
GitHub Sponsors:
https://github.com/sponsors/sonertari
Buy me a coffee:
https://buymeacoffee.com/sonertari
thanks.dev:
https://thanks.dev/u/gh/sonertari
GitHub.io:
https://sonertari.github.io
Open post
Soner Tari @sonertari@infosec.exchange
· 7mo ago

Is HTTP/2 the "Final Boss" for open-source firewalls? 🛡️

For years, we’ve been forced to "downgrade" traffic just to inspect it. As a FOSS developer, I spent months trying to bridge the gap between HTTP/2 and legacy inspection tools in SSLproxy.

The result? A "Concurrency Density Spike" that can overwhelm even the best C-based proxies. 📈

In my latest article, I break down why we need to stop fighting the "Binary Frame" war and start focusing on the ICAP Path. It’s not just a fix for H2—it’s our only real ticket to supporting HTTP/3 (QUIC) and finally unblocking UDP port 443 without losing visibility.

#OpenSource #CyberSecurity #InfoSec #NetworkSecurity #HTTP2 #HTTP3 #SSLproxy #Suricata #Firewall #ICAP #SystemArchitecture

https://www.linkedin.com/pulse/i-tried-add-http2-sslproxy-here-why-stopped-we-need-icap-soner-tari-7x7mf

Infosec Exchange

2
0
3
0
Open post
Soner Tari @sonertari@infosec.exchange
· 15mo ago

My FOSS SSLproxy Needs HTTP/2 Support for Next-Gen Network Security (The "Invisible Threat" is Growing)

I'm the long-time maintainer of SSLproxy (and the co-maintainer of SSLsplit), a unique open-source transparent SSL/TLS proxy. Its core strength lies in its ability to decrypt and divert network traffic to other security tools (like E2guardian, Snort IPS, POP3 proxy, SMTP proxy, Virus and Spam scanners as in my UTMFW firewall) for deep SSL inspection. It's truly the only FOSS tool offering this transparent, real-time diversion capability to enable UTM services on encrypted streams. (For context: popular tools like mitmproxy, while powerful, expect you to write/use extensions for inspection rather than diverting traffic for existing services.)

The Problem: HTTP/2 is Hiding Threats in Plain Sight

In 2025, nearly a third of all websites have adopted HTTP/2. Here's the critical challenge for open-source cybersecurity: Current FOSS security tools, including SSLproxy and many downstream listening programs (like E2guardian, Squid, Snort), often cannot fully understand or process this HTTP/2 traffic in real-time. This is a significant gap, as commercial closed-source firewalls and libraries do offer real-time HTTP/2 SSL inspection capabilities. (For context: there are open/closed-source solutions for offline analysis.)

Currently, SSLproxy either prevents HTTP/2 upgrade or allows you to bypass HTTP/2 traffic using its powerful filtering features. However, neither offers the deep, real-time inspection needed for comprehensive security.

This creates a dangerous "translation gap" in the open-source ecosystem, where a growing portion of encrypted internet traffic is effectively invisible to real-time deep inspection, forcing reliance on proprietary solutions for full visibility.

Why This Matters for You:

  • Deep Inspection is Blind: Without real-time HTTP/2 support, the vast majority of modern encrypted traffic bypasses essential content filtering, intrusion detection, and virus scanning that FOSS tools could otherwise provide.
  • Essential for UTM: Projects like my UTMFW heavily rely on SSLproxy to feed decrypted traffic into their core services. Lacking HTTP/2 support in SSLproxy (and integrated UTM services) means a critical blind spot in next-gen firewall capabilities.
  • Security Professionals Need It: If you're a cybersecurity professional relying on FOSS tools to inspect TCP, SSL/TLS, and HTTPS traffic for analysis, this directly impacts your ability to gain full visibility into modern network communications.

The Solution & The Challenge Ahead:

SSLproxy must evolve to natively speak HTTP/2 and transparently translate it back to HTTP/1 for seamless integration with existing downstream security tools. This is a substantial engineering effort, requiring the integration of complex libraries like nghttp2 and nghttpx, and a dedicated focus.

How You Can Help Fuel This Critical Work:

My FOSS projects are fueled by a deep commitment to open-source security, but developing and maintaining these complex, vital features demands significant time and resources. If you or your organization benefit from open-source network security tools like SSLproxy, your support is invaluable.

Sponsorship enables me to dedicate full-time effort to delivering crucial advancements like comprehensive HTTP/2 support, improved TLS compatibility, Windows support, and much more.

You can learn more about SSLproxy, UTMFW, and my other projects, including the full roadmap, here:

➡️ My New Website: https://sonertari.github.io

➡️ GitHub Project Boards (Full Roadmap): https://github.com/sonertari?tab=projects

#FOSS #Cybersecurity #NetworkSecurity #OpenSource #InfoSec #SSLproxy #UTMFW #HTTP2 #Firewall #IPS #Sponsorship #ComixWall

1
0
0
0
Open post
Soner Tari @sonertari@infosec.exchange
· 10mo ago

UTMFW/PFFW/PFRE 7.8 released: https://github.com/sonertari/UTMFW/releases/tag/v7.8

0
0
0
0
Open post
Soner Tari @sonertari@infosec.exchange
· 10mo ago

SSLproxy 0.9.9 released: https://github.com/sonertari/SSLproxy/releases/tag/v0.9.9

0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)
  • Source code

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 17:42:59 UTC