Hacker News new | ask | show | jobs
by gruez 1772 days ago
>Probably doing MITM SSL inspection.

Probably not, judging by the gp's use of the term "end to end encrypted". Nearly every site uses HTTPS, so if they were really doing MITM, either everything would be broken (because the root certs aren't installed), or everything works. My guess is that his employer's network has some sort of network filter installed, and "end to end encrypted" is a classification category for sites that is blocked for whatever reason.

1 comments

HTTPS is not an obstacle to this.

As I mentioned before, the methodology requires publishing a trusted cert to endpoints. This is done with GPOs or whatever RMM tool is used to manage workstations + MDM to push to mobile.

You will find this implemented in nearly any high-security network environment (finance, government, etc.), primary schools, and a lot of miscellaneous businesses.