Why we assume TLS? Also the packet sniffing can be done on either hosts at source before TLS applied meaning layer 2? Data Link Layer?, AFAIK TLS is applied in Layer 4, Transport layer. So having something hijack the kernel modules would do that. Or having an extraneous root CA in the hosts... if the hosts were so open this is so easy to achieve.
Either way lets say it was properly encrypted still the source/target IP addresses can be read from traffic logs right?
Why we assume TLS? Also the packet sniffing can be done on either hosts at source before TLS applied meaning layer 2? Data Link Layer?, AFAIK TLS is applied in Layer 4, Transport layer. So having something hijack the kernel modules would do that. Or having an extraneous root CA in the hosts... if the hosts were so open this is so easy to achieve.
Either way lets say it was properly encrypted still the source/target IP addresses can be read from traffic logs right?