Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I thought it's standard practice to MITM at the workplace. How else can you flag exfiltration of sensitive information and stop incoming malware? Add a certificate to browsers on employee's computers, encrypt on proxy after inspection.


I've literally in a 25 year IT career only worked at one place which did TLS MITM, and that's a place that works extensively with GCHQ.


This still breaks TLS, since it will fail with client-supplied certificates and so can't be used if you need to support TLS.


Computers owned by the firm have extra CAs installed. All browsers allow admins to add CAs. Unsophisticated users will never know that e.g. BlueCoat shitboxes (and everyone who has pwned those shitboxes) are reading all their TLS traffic.


But the web servers on the other side of the TLS connection are not managed by those same system administrators and therefore they will not accept certificates provided by such proxies, breaking TLS.


To the external server, the shitbox is the user. To the user, the shitbox is the external server. Talk to IT/Networking people at any large firm; this is how it has worked for years.

Client certs are a different thing entirely, and unrelated to this discussion.


How are client certificates, a mandatory feature of TLS and specifically what I mentioned, and what you are replying to, unrelated to this discussion ?


What is this "mandatory feature" stuff? We're talking [0] about employees on websites "protected" by TLS, and expecting privacy while doing so. If they order hemorrhoid cream on Amazon, their browser talks to the shitbox, the shitbox talks to Amazon, and client certs have nothing to do with that. The browser verifies that it trusts the shitbox, and nobody else verifies anything.

One supposes there might be some banks or B2B sites that might use client certs, but they're such a minority that no one ever heard of them.

[0] https://news.ycombinator.com/item?id=16186735


Client certificates are a mandatory feature of TLS that any TLS server could request and the proxy would be unable to handle the request, as it (and ideally the client) has no access to the private key. Therefore, these types of proxies break TLS by being unable to support mandatory features.

Separate from that, client certificates are certainly common, being used for authentication, in the US Federal Government, which issues tens of millions of certificates for this purpose as well as smartcards, since George W. Bush banned passwords with HSPD-12.


The shitboxes definitely "break" TLS. That's why firms buy them in the first place. A firm that was using smartcards with the characteristics you describe would presumably figure out something other way to pretend to prevent data exfil.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: