3 ms·
Default configurations – without tampering by corporate admins – are of course immune. Application layer developers are fighting corporate TLS interception wit
by floatboth 6y ago
Default configurations – without tampering by corporate admins – are of course immune.
Application layer developers are fighting corporate TLS interception with things like certificate pinning, not using the OS certificate store, making it harder to modify the app's certificate store. The goal is to heavily discourage corporations from breaking end-to-end security to spy on their employees.
- jlokier 6y agoIt is relatively easy to override certificate pins by modifying the browser that's installed on the corporate network. In those places where they are adding a "trusted" local middlebox CA to the client for interception, modifying the browser's pin store (or its logic) is not such a big stretch on top of that. At least other devices, such as users own devices on the corporate network, are immune to this.