Hacker News new | ask | show | jobs
by chikere232 610 days ago
If someone makes you import a CA, you have to assume they intend to eavesdrop on ssl encrypted communications. Enterprise WPA doesn't require it.

The right flavour of incompetence might get you there without bad intentions but really if you give someone the capability of eavesdropping you have to behave as if they're intending to use it

1 comments

Doesn't seem like it. For instance the WPA enterprise setup dialog has a field specifically for a CA certificate[1]. Other OSes have something similar [2]. Presumably that's only used for WPA authentication purposes rather than being added as a sytem CA.

[1] https://askubuntu.com/questions/1317320/how-can-i-automatica...

[2] https://documentation.meraki.com/MR/Encryption_and_Authentic...