4 ms·
> proxying for third-party sites does not allow for this in its current implementation without introducing man-in-the-middle capabilities Since they're just pr
by macns 11y ago
> proxying for third-party sites does not allow for this in its current implementation without introducing man-in-the-middle capabilities
Since they're just proxying, it makes sense to abandon encryption all together, not? I mean after all, HTTPS is supposed to protect from man-in-the-middle attacks, but aren't they themselves exactly that?
- pjc50 11y agoYou can have HTTPS proxies which only connect to a predefined list of IPs if you want. Because this is a surveillance-value-based product, they don't want to do that. (Given the Indian govt vs Blackberry, I wouldn't be surprised to hear that they had a hand in this somewhere. Very convenient if all mass political organisation goes through unencrypted facebook...)