|
|
Log in / Subscribe / Register

corporate IT administrators

corporate IT administrators

Posted Mar 8, 2016 16:26 UTC (Tue) by raven667 (subscriber, #5198)
In reply to: corporate IT administrators by josh
Parent article: TLS certificate management on Android

> But I don't think browsers should do *anything* to make it easier to MITM HTTPS traffic; no matter the path to the proxy, the proxy itself should continue using CONNECT or similar to pass through HTTPS traffic unmodified.

The purpose of the proxy is to inspect the cleartext to block malware, or network usage that violates the policy of the owner, when the same administrative entity owns the network and edge equipment. The problem is that anything which makes it easier to MITM for legitimate security reasons, also can be used by bad actors to transparently intercept traffic in ways that are difficult to detect for the average person. The browser vendors are making the policy decision that protecting people from repressive governments or criminal organizations is more important than enabling inspection by admin policy.


to post comments

corporate IT administrators

Posted Mar 8, 2016 18:01 UTC (Tue) by nim-nim (subscriber, #34454) [Link] (4 responses)

Actually, they're not protecting anyone. It's easier to grandstand publicly than actually cut proxies and deal with the backlash of all their users. So they end up supporting the worst kind of MITM officiously, instead of working to make it as safe as possible and under user control.

And yes like any useful tech it can be used for evil purposes. Let's kill mail to put an end to spammers.

corporate IT administrators

Posted Mar 8, 2016 18:38 UTC (Tue) by raven667 (subscriber, #5198) [Link] (3 responses)

> Actually, they're not protecting anyone. It's easier to grandstand publicly than actually

If you can't even understand or acknowledge the perspective of the people you are arguing with, how do you expect to effectively communicate your point? Changing minds requires a dialog not a monologue.

corporate IT administrators

Posted Mar 8, 2016 22:19 UTC (Tue) by nim-nim (subscriber, #34454) [Link] (2 responses)

I'm sorry, but what exactly are you taking offense at?

Did I write anything but the truth?

Am I wrong when I state that despite vehement public opposition to the idea, browser people make sure year after year that it is possible to MITM connexions by importing CAs in their certificate stores? That is a fact and easily checked by consulting browser changelogs.

Am I wrong when I state that making standard communication with proxies obsolete, by refusing to overhaul it with the rest of the web stack, only pushed corporations and security providers to convert massively to the worst and most dangerous kind of MITM? Who targets anything else nowadays?

Am I wrong when I state the people browsers claim to "protect", actually use the tech browsers want to ban (proxies), to protect themselves (for example to bypass the great firewall of China)? That this technology is by no means as one-sided as the browser discourse wants you to believe?

Am I wrong when I state that refusing to give browser users the interfaces to check whom they are giving access to, only results in having this access taken without control?

What, exactly, is accomplished by continuing to push for an ideal state, while enabling its exact reverse year after year, since society is not ready for this ideal state today (will it ever be?) Would it be such a defeat to give browser users a middle ground solution now, instead of waiting for a complete victory that refused to happen for at least a decade?

And, BTW, I do not mean ideal in the positive sense. I mean ideal in the imaginary sense. We've left the point, when one could imagine connecting to the Internet, without firewalls and other security tools, a long time ago. Refusing to secure the network, because browsers have their own security, is irresponsible (first, all connexions are not made via browsers, and second, even if they were, why should we trust browsers absolutely?)

corporate IT administrators

Posted Mar 9, 2016 1:57 UTC (Wed) by raven667 (subscriber, #5198) [Link] (1 responses)

I wsnt taking any offence, I was providing advice on how to better communicate your point, which you seem to have completely missed, and kind of underlines what I was saying.

corporate IT administrators

Posted Mar 9, 2016 18:33 UTC (Wed) by nim-nim (subscriber, #34454) [Link]

Please realise, that taking the higher moral ground ("protecting people from repressive governments or criminal organizations") while refusing to discuss facts that contradict this manichean view, is highly inflammatory in itself.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds