Google: Maintaining digital certificate security
Google: Maintaining digital certificate security
Posted Mar 24, 2015 21:17 UTC (Tue) by robbe (guest, #16131)In reply to: Google: Maintaining digital certificate security by ledow
Parent article: Google: Maintaining digital certificate security
> that's why you use your own certificate chain and add it to the machines
> somehow (even on BYOD setups).
But it's not easy nor convenient to do at scale, especially not for for Firefox¹ or mobile devices. For BYOD it may actually incur legal risk².
We sell these MITM proxies at work, and about once a month I have to explain to a customer:
Customer: I want to <X>
Me: You must turn on HTTPS inspection for that to work.
Customer: But the manual says I then have to install a certificate on every device. That's so much bother! Isn't there a better way?
Me: No legal one, no.
¹ Gerv, you still listening? That's my number one pain point for FF on enterprise desktops.
² If I do e-banking from this MITM-ready device, non-repudiation conveniently goes out the window.
Posted Mar 24, 2015 23:00 UTC (Tue)
by josh (subscriber, #17465)
[Link] (4 responses)
Good. It should be absurdly hard. If it were easier, more people would do it.
Posted Mar 24, 2015 23:18 UTC (Tue)
by pboddie (guest, #50784)
[Link]
Posted Mar 25, 2015 6:44 UTC (Wed)
by epa (subscriber, #39769)
[Link]
Posted Mar 26, 2015 21:30 UTC (Thu)
by robbe (guest, #16131)
[Link] (1 responses)
Unfortunately, the employer will just stay with IE in this case. Not installing Firefox is certainly easier than rolling it out *and* fudging one or more certificates into its trusted store.
Maybe a better way is to make adding a MITM cert easier, but show a different visual cue in the "security indicator" next to the URL. Example:
Padlock: we're pretty sure nobody can listen in
Posted Mar 26, 2015 22:19 UTC (Thu)
by josh (subscriber, #17465)
[Link]
As far as the right to do so: in my opinion, the provider of a network can intercept traffic if they want, but should not be allowed to do so without notice and consent.
Posted Mar 25, 2015 11:52 UTC (Wed)
by rich0 (guest, #55509)
[Link]
Posted Mar 25, 2015 12:34 UTC (Wed)
by gerv (guest, #3376)
[Link]
Gerv
Google: Maintaining digital certificate security
Google: Maintaining digital certificate security
Google: Maintaining digital certificate security
Google: Maintaining digital certificate security
Stethoscope: someone is watching your decrypted traffic, ostensibly for malware, but insulting your boss or planning a coup is probably not a good idea either
Megaphone: only politeness protects you, don't do anything you wouldn't do in the cafeteria
Google: Maintaining digital certificate security
Google: Maintaining digital certificate security
Google: Maintaining digital certificate security