|
|
Log in / Subscribe / Register

corporate IT administrators

corporate IT administrators

Posted Mar 10, 2016 21:25 UTC (Thu) by bronson (subscriber, #4806)
In reply to: corporate IT administrators by paulj
Parent article: TLS certificate management on Android

A permissions dialog is going to pop up on every new connection? It sounds like the net security effect is mostly in making it unusable.

I'd hazard that approximately 100% of network owners wouldn't want this, and 99.9% of network users wouldn't want it either.


to post comments

corporate IT administrators

Posted Mar 11, 2016 12:13 UTC (Fri) by nim-nim (subscriber, #34454) [Link] (4 responses)

Sure, let's implement it the dumbest way possible, and then remove it because the implementation is dumb.

corporate IT administrators

Posted Mar 13, 2016 3:49 UTC (Sun) by bronson (subscriber, #4806) [Link] (3 responses)

Isn't that exactly what you proposed?

> You show the user the proxy URL, you show the user the proxy cert, and you ask if he authorizes proxying by this entity.

corporate IT administrators

Posted Mar 14, 2016 14:09 UTC (Mon) by nim-nim (subscriber, #34454) [Link] (2 responses)

I never proposed "A permissions dialog is going to pop up on every new connection"

In fact I explicitly wrote about needing an UI to handle revocations, ie the browser remembering the permissions till the user revokes them.

corporate IT administrators

Posted Mar 14, 2016 19:24 UTC (Mon) by bronson (subscriber, #4806) [Link] (1 responses)

Curious then, how else are you going to show the proxy URL and cert, and wait for permission? (Gnome and KDE experience has shown that notifications aren't enough.)

corporate IT administrators

Posted Mar 16, 2016 15:29 UTC (Wed) by nim-nim (subscriber, #34454) [Link]

Sure you need to show the "do you trust xxxx to proxify your traffic" dialog. But once not every time you connect.

I won't say that's trivial, but that's not *that* hard. Browsers do such messages all the time when there is something they don't like (dns, cert, etc).

On an ideal properly integrated desktop that would go on the network connexion widget like wifi passwords and vpns (from a functional POW a proxy is a pure HTTP/s VPN)


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds