Wouldn't that require them to MITM the Netflix traffic, which I would hope is under TLS?
Wouldn't that require them to MITM the Netflix traffic, which I would hope is under TLS?
Netflix calls it their Open Connect Appliance: https://openconnect.netflix.com/en/appliances/
That server would, of course, have a connection to the Internet, they push logs to AWS and get updates from Netflix's authoritative servers in Netflix's other datacenters, but they also serve HTTPS connections to thousands of ISP users; the upstream traffic would be minimal.
I believe YouTube has the same type of program.
This problem might also be an interesting use case for Signed HTTP Exchanges. Sign the video files, then push them to the caching server. The caching server then never possesses the private keys for the connection and also cannot modify the content.
What are you going to achieve by stealing the certificate for edge0.sktelecom.geo.netflixcdn.com from the box you already have access to?
There’s no reason to put *.netflix.com certs on the edge caches.
Versus, what's the attack? The ISP with physical access to the box can pull can screw with the cached video data somehow? Or MitM and know what Netflix videos their users are watching?