5 ms·
"Is it necessary to have a local trust store that can override HPKP pins in order to debug a TLS connection? No, it is not." Isn't that exactly what is needed
by posnet 11y ago
"Is it necessary to have a local trust store that can override HPKP pins in order to debug a TLS connection? No, it is not."
Isn't that exactly what is needed in a corporate or home network where the administrator wishes to monitor/proxy tls/ssl traffic?
Whether that is OK or a good idea is a whole other discussion, but maybe I am misunderstanding the authors point.
- lostcolony 11y agoThe author flat out says a toggleable debug mode to allow that. Something like a command line flag on starting Chrome to explicitly disable that behavior. You know, like all the other testing flags Chrome has.
- JoshTriplett 11y agoThat doesn't mean it needs to happen silently; such interception should result in an unremovable browser indicator warning that it looks like your traffic is being intercepted. If you consider it acceptable for the network you're on to intercept your traffic, then you can certainly continue to browse despite that warning. You might decide not to transact any private business on such a network, of course.