|
|
|
|
|
by dogma1138
2665 days ago
|
|
Decrypting traffic on the client isn’t always possible due to how modern browsers operate. Decrypting traffic on clients is also much harder due to the multiple types of clients you have and the fact that there is no easy way to MITM every connection the the client. The security threat model by definition defines clients as untrustworthy hence relying on them for decryption is a flawed approach. If you are going to be cocky and disrespectful at least be right. |
|
Yeah, it's a hard problem. If you don't know half the things your clients are doing, it's much easier to pretend all the security conscious stuff will be going through TLS and then we break just that. It's also obviously wrong, as we all learned when they started filling USB ports with glue.
The boxes already rely on the client, unless someone signed another CA=yes certificate.