4 ms·
> Installing organization-specific self-signed roots in all company devices is more than just 'a pain'; it's fundamentally impractical for any organization that
by nupark2 15y ago
> Installing organization-specific self-signed roots in all company devices is more than just 'a pain'; it's fundamentally impractical for any organization that wants to let employee-owned or public devices onto its network. So just don't do that?
Yes, just don't do that. There are sufficient mechanisms to distribute security policy configuration to company devices.
Silently sniffing traffic from external, personal devices is unequivocally unacceptable. I would be livid to know that a company was silent pretending to be my bank, my e-mail provider, or even just Amazon without my prior consent. Having to explicitly trust their internal CA is exactly how that consent is supposed to be provided.
The CA system's trustworthiness is fundamentally broken. I am austounded that Mozilla did not immediately remove the CA certificate from the trusted set.
- tptacek 15y agoCompany's network, no privacy, full stop. Pick your battles. The problem isn't that a company wanted to MITM SSL traffic on its corporate network. The problem is that a CA was willing to allow them to hijack the whole CA system so they could do it on the cheap.
- nupark2 15y agoI think you either misread, or I was unclear -- we're in agreement. Company network with company devices: sniffing traffic is fine, insofar as it's done by configuring the devices with a private CA. Company network with personal devices (including visitor's devices): silently MITMing SSL using forged certificates and a real CA is not fine. They can either forbid the use of personal devices, or request that I install their internal CA.