Hacker News new | ask | show | jobs
by gzread 103 days ago
You're lucky the browsers eventually relented and allowed custom root certs. That was seen as a vulnerability and almost patched.
1 comments

Yes, and the next battle is ech-pinned params in apps. The browser can at least single that ech isn't supported. For apps, you'll just have to strip the ech and downgrade the connection and live with the server dropping you. But that's fine. My kids don't need tiktok if I, the parent, can't decrypt the info.