corporate IT administrators
corporate IT administrators
Posted Mar 10, 2016 9:24 UTC (Thu) by paulj (subscriber, #341)In reply to: corporate IT administrators by nim-nim
Parent article: TLS certificate management on Android
You're complaining that the browsers are somehow refusing to reasonably act in providing a MITM vector friendly to corporate proxies to monitor traffic of users' who are contractually (and lawfully) obliged to agree to such monitoring. The problem is there no known way to implement this that doesn't also give bad guys a MITM vector.
Please explain exactly how a browser, acting on behalf of a user, is supposed to distinguish between a MITM proxy that the user /should/ allow and one it should not?
It has to be technically possible and implementable, otherwise you're just howling at the moon.
