Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> so blocking it will be very hard without also blocking regular HTTP TLS traffic.

Many large or data-sensitive companies do SSL MiTM at their firewall so unfortunately that's not hard at all.



true, but then you're not in a {censorship, attacker} free environment at all -- MITMing TLS _is_ violating the security expectations of today's websites. I wouldn't even check my non-work email.

i.e. all bets are off. there will always be pockets. but over time we could win even there, as the perf improvement will matter.


This is a minority though and the users on such nets have pretty diminished expectations on the level of net access they have.

(It's also illegal BTW in civilized countries! At least on networks with employees doing web browsing, as that's personal communications of the employee and and part of fundamental rights)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: