3 ms·
Google Chrome allows TLS MITM proxies to override HPKP settings (which is not without controversy): We deem this acceptable because the proxy or MITM can only
by tshtf 11y ago
Google Chrome allows TLS MITM proxies to override HPKP settings (which is not without controversy):
We deem this acceptable because the proxy or MITM can only be effective if the client machine has already been configured to trust the proxy’s issuing certificate — that is, the client is already under the control of the person who controls the proxy (e.g. the enterprise’s IT administrator). If the client does not trust the private trust anchor, the proxy’s attempt to mediate the connection will fail as it should.
https://www.chromium.org/Home/chromium-security/security-faq#TOC-How-does-key-pinning-interact-with-local-proxies-and-filters- https://www.chromium.org/Home/chromium-security/security-faq...
https://code.google.com/p/chromium/issues/detail?id=561646 https://code.google.com/p/chromium/issues/detail?id=561646
- pfg 11y agoFirefox defaults to the same implementation[1]. I'm personally fine with this. MITM proxies are a valid use case. I do think that all parties should be made aware of it, but that's probably something that has to be fixed via laws (I think some European countries forbid this practice unless it's been made clear that there can be no expectation of privacy on a company-provided device). [1]: https://wiki.mozilla.org/SecurityEngineering/Public_Key_Pinning#How_to_use_pinning https://wiki.mozilla.org/SecurityEngineering/Public_Key_Pinn...