After GN’s and Wendell’s investigation in to LG TV’s atrocious practices with regards to ACR (automatic content recognition) and listening in on conversations even though I did not give my consent, or I missed the double opt-out, when all I wanted to do is just do a firmware update of my TV, I was wondering if other devices in my home are also selling my data.
My approach until now was to have a separate network for these kind of devices, and to also not use their internet functionality unless I had a good reason to, but now I realize that this approach is a bit naive on my part, because even though I can filter connections through a firewall, I actually don’t know what is going through those connections.
Being involved with a bunch of security applications at work, I naturally thought that the obvious solution for something like this would be DLP (Data Loss Prevention), where I would have a network for the devices I don’t fully trust where I could break TLS encryption, scan what’s going outbound, then re-encrypt the data before sending it on. Now, this would involve me rolling my own private CA and installing it on the trust store of the devices that I presumably “own”, and also installing and configuring a MITM proxy like Squid. I realize that not all devices will have the option of installing my own certificate, even if I jailbreak them, but if they don’t then I’m ok with them loosing whatever functionality they offered by connecting to the internet.
My only problem with such a setup is that I don’t know but also don’t have experience with any open-source DLP solution. I saw MyDLP and OpenDLP, but they haven’t been updated since what feels like the dawn of time, at least the OSS version. Then there are solutions like Snort, which is mainly an IDS/IPS, but it seems to have a Sensitive Data Preprocessor module which can act as a rudimentary DLP solution, but I have no idea how I would tie it with Squid. One other option that I saw mentioned online is Security Onion, that relies on Suricata, but, from what I can tell, I would only have the option to use regex but it seems like a very heavy & complicated solution.
I realize that whatever solution I choose it will be a nightmare to manage, until I find a happy medium between false-positives and the level of protection the policies would offer me. But anyway, does anyone have any experience with OSS DLP solutions that would work for this scenario? What is your setup? How are you using it?