|
|
|
|
|
by fc417fc802
79 days ago
|
|
I don't believe it's supposed to proactively check the logs as that would inevitably break in the presence of properly configured MITM middleboxes which are present on many (most?) corporate networks. The point of the logs as I understand it is to surface events involving official CAs after the fact. |
|
And yes, it does break MITM use cases, for example on Chrome: https://httptoolkit.com/blog/chrome-android-certificate-tran...