|
|
|
|
|
by PeterisP
1755 days ago
|
|
Basic TLS is sufficient to stop your employer from MITM'ing your personal email session as long as you control what certificates your machine trust. Certificate pinning is what protects the main sites (who use pinning) from an advanced attacker or a rogue government who are able get a proper CA to issue fake certificates. |
|
Which, on almost any employer-issued device on a large corporate network today, you won't.
Personal stuff goes on personal devices with personal connectivity and uses personal accounts with personal security. Work stuff goes on work devices with work connectivity and uses work accounts with work security. Contaminating either with the other is just a recipe for bad things happening, often for both the employer and the employee.