4 ms·
If you trust a company's internal CA then aren't you trusting them to issue certificates for every website and not just their own? Isn't that dangerous?
by wfunction 9y ago
If you trust a company's internal CA then aren't you trusting them to issue certificates for every website and not just their own? Isn't that dangerous?
- bjpbakker 9y agoYes absolutely. If I have to I trust the company's CA in a special browser profile that I only use for working with their internal tools. For just a few tools it's often simpler to just trust those specific certificates, though
- ewanm89 9y agoAll browsers can tell you what certificate signed the one in use. Unfortunately a recent chrome UI change made this a pain to get to.in chrome, into the other browsers just clicking on the lock in the address bar, it soon becomes obvious if the company is mitm all SSL connections.
- wfunction 9y agoBecause a normal person will "just click the lock in the address bar" on every single HTTPS website he visits to make sure his company isn't MITMing him, right?