Hacker News new | ask | show | jobs
by jessaustin 4533 days ago
Oy. Students at your university certainly have my sympathy.

I've always been leery of the mitm cert, not only from the users' perspective, but also from that of the organization. If a rogue administrator used the cert to set up a "real" mitm for a local bank's site, I think the school would be on the hook for that. That's just one example; one could imagine other variations on that theme. Whereas, if the school simply acted as a normal ISP, that whole class of vulnerabilities simply doesn't apply.

1 comments

I believe Stanford does something similar (as well as forces you to install Sophos bloatware)