3 ms·
The simple(ish) solution is to install a firewall on your network and configure it to MITM all the HTTPS traffic and simply deny anything it can't MITM. I under
by d110af5ccf 5y ago
The simple(ish) solution is to install a firewall on your network and configure it to MITM all the HTTPS traffic and simply deny anything it can't MITM. I understand this to be standard practice in many corporate environments. The device/app/whatever either trusts your CA or the traffic gets blocked. I don't bother to do so myself but I think it's a good position to take. My network is mine.
- 1vuio0pswjnm7 5y agoThat is what I was doing (and still do). I wanted to learn how to do it on a smaller form factor device. For example, imagine a firewall in the form factor of a smartphone. I have seen at least one other person on HN who says they are using a pocket-sized gateway/firewall. Intentional "MITM" is obviously a common topic that gets discussed on HN from time to time. What bothers me about HN commenters on this topic is that they signal that they are familiar with what needs to be done, i.e., to MITM their own traffic, and want us to know they understand how one "could" do it, however it is unclear that they themselves are actually doing it. I sometimes wonder if this is tacit approval of TLS being used (strategically perhaps) to lock users out of monitoring their own computers and computer networks. Hopefully there are many HN readers who do monitor ther own traffic but are generally not commenting about it.