Hacker News new | past | comments | ask | show | jobs | submit login

I don't think they need to get one; Take a look at the CAs are in your browser. Do you implicitly trust all of those organizations and governments? It doesn't matter if you do as your browser already does.



This hasn't been the case since Chrome implemented certificate pinning in 2011.


Chrome pinning doesn't break corporate MITM proxies.

https://www.imperialviolet.org/2011/05/04/pinning.html


Obviously, if they can install additional Root CAs, they have enough access to do absolutely anything as your user on your maxhine, including installing trojaned versions of all your apps. That isn't the issue gp was discussing.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: