4 ms·
The OP was correct. Yes TLS inspection exists, but requires a special CA certificate installed on the device. Yes, state actors have compromised CA's. Yes yes y
by nodesecurity 7y ago
The OP was correct. Yes TLS inspection exists, but requires a special CA certificate installed on the device. Yes, state actors have compromised CA's. Yes yes yes it's all possible and does happen. No, you're not being MITM'ed when you connect to a restaurant wifi.
If everything needs to be qualified to the millionth degree, with every caveat laid out and explained, we won't have time to discuss interesting things. The OPs comment is correct general advice.
- _jal 7y agoI'm well aware of how inspection works. You are more than welcome to make your own risk evaluations, but you're looking at this through too narrow a lens. The OP may be sort-of correct for your average first-world facebook-phone user with "nothing to hide", so I kind of agree with your last sentence. But it is way too blithe and unconcerned, and, well, they won't be the first self-described "security expert" who's judgement I find lacking.