corporate IT administrators
corporate IT administrators
Posted Mar 6, 2016 23:15 UTC (Sun) by tialaramex (subscriber, #21167)In reply to: TLS certificate management on Android by josh
Parent article: TLS certificate management on Android
Out of the box, the McAfee Web Gateway's built-in CA certificate (used to sign certificates pretending to be Google, Amazon, LWN, HSBC, the British Government and so on) is of course not trusted by anybody. But you can force every corporate computer to add this CA cert to its trust store and so that's what this FTSE 100 Company have done. That way you shut up all the anti-MITM features. In fact (contrary to what you might expect if you believed Nim-Nim's rants) browser vendors go out of their way to allow this to work, because corporates insist upon it.
Having this single point of failure in your security infrastructure isn't a good idea, but in principle it /could/ work and not be that much more dangerous than not having the MITM proxy. There's really only one problem. McAfee Web Gateway isn't a custom solution developed for that one FTSE 100 Company, it's a commercial product, anybody can buy one (under a variety of names, the core software is the same). So the effect of adding "McAfee Web Gateway" to a computer's trust store is to allow anybody who has purchased the product, or who has obtained the private key from a legitimate purchaser's product, to impersonate literally any SSL site to all employees of the FTSE 100 Company.
To be fair to them, Intel / McAfee do document this problem in the product manual, and doubtless if any actual smart, security-minded people were buying MITM proxies they'd ask "So, how do we attach this to the HSM we use as a responsible corporation to do our PKI?" and have it all explained. But the average corporate IT administrator at a non-software company (even with a multi-billion dollar market cap) is happy that they spent a five figure sum of money on "securing web access" and they can check that off their Information Security checklist. If you explain to them that actually they've completely undermined a crucial element of the security infrastructure they'd be dumbfounded, they paid thousands of dollars, how can that not mean their security is better ?
