Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This hasn't been the case since Chrome implemented certificate pinning in 2011.


Chrome pinning doesn't break corporate MITM proxies.

https://www.imperialviolet.org/2011/05/04/pinning.html


Obviously, if they can install additional Root CAs, they have enough access to do absolutely anything as your user on your maxhine, including installing trojaned versions of all your apps. That isn't the issue gp was discussing.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: