LWN.net Logo

Liability

Liability

Posted Jul 16, 2012 11:37 UTC (Mon) by robbe (guest, #16131)
In reply to: That's what dot1x is for by hummassa
Parent article: Cyberoam deep packet inspection and certificates

> If you have a real-world big organization, you shoudn't snoop people's bank
> account passwords[...]

Hereabouts organisations solve that problem by a combination of:
* forbidding private use of their Internet connection
* informing employees that their Internet traffic can be monitored, even HTTPS

The nicer companies allow exceptions (e.g. private surfing during breaks) but put the onus on their employees to inform them of websites that should never ever be snooped upon. A whitelist of sites that are not MITMed is a standard feature of these SSL scanner products.

I see a much bigger problem at the moment with mobile devices that can jump from unsecured (e.g. 3G) to a privileged (e.g. company WLAN) net in seconds ... sometimes without the user even noticing.


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds