Hacker News new | ask | show | jobs
by codeka 5083 days ago
This is far more common than you might expect. You just need to push you're company's internal CA to all your client computers, and bam, MITM for everything!
1 comments

Yes enterprise customers want to decrypt and inspect all traffic, for legitimate and sometimes sketchy reasons.
HIPAA requires it as far as I know, and I am sure other regulatory frameworks probably do.
HIPAA does not require traffic monitoring.