|
|
|
|
|
by abrodersen
3457 days ago
|
|
Browser vendors should show a security warning when encountering this behavior. Default configurations of all software must be to disallow. The burden should be on the enterprise to configure their client devices to allow MITM. |
|
There are already plenty of ways for enterprises to get around this, like having their own CA and deploying that as a trusted CA to their machines. Then they can issue certs that their proxies could use, and their machines would just trust those certs.
Why don't they just use that method?