corporate IT administrators
corporate IT administrators
Posted Mar 7, 2016 16:29 UTC (Mon) by josh (subscriber, #17465)In reply to: corporate IT administrators by nim-nim
Parent article: TLS certificate management on Android
If anything, browsers need to make MITM attacks harder: when they see a site with a pinned certificate using a different certificate that's in the browser trust store, they should make that MITM visible to the user.
This isn't about browsers ceding their own control; this is about browsers keeping the user safe and in control.
For that matter, browsers have a long history of targeting the end user, not the corporate IT department; many people have fond memories of installing Firefox (or Mozilla before that) on systems that were "supposed" to run IE.
