3 ms·
Extensive proxying? MITM? There's no reason they wouldn't put their own root certificate onto the machines. For most work on Wall Street one probably doesn't ev
by die_sekte 16y ago
Extensive proxying? MITM? There's no reason they wouldn't put their own root certificate onto the machines. For most work on Wall Street one probably doesn't even need to be connected to the internet.
- arethuza 16y agoIt's scary the number of people who think that HTTPS guarantees an end-to-end secure channel between your browser and the remote application.
- die_sekte 16y agoWell, it does if you control the machine you're using. Or am I missing something?
- arethuza 16y agoAFAIK if someone else controls the machine you are on (or can get certs installed by one way or another) which can be combined with a MITM proxy to get access to the unencrypted content. However, a lot people use machines they don't control where this kind of approach is perfectly feasible.