|
|
|
|
|
by atmosx
4497 days ago
|
|
Actually I did, here are the relevant parts[1]: uers should be made aware that, different than end-to-end HTTPS, the achievable security level is now also dependent on the security features/capabilities of the proxy as to what cipher suites it supports, which root CA certificates it trusts, how it checks certificate revocation status, etc. Users should also be made aware that the proxy has visibility to the actual content they exchange with Web servers, including personal and sensitive information. Now the question is, did you??? I've seen the link[2] you posted and I didn't find ANYWHERE the part where it specifically talks about HTTP and not HTTPS. There's even the above part explaining making things even more complicated... [1] http://tools.ietf.org/html/draft-loreto-httpbis-trusted-prox... [2] http://hillbrad.typepad.com/blog/2014/02/trusted-proxies-and... |
|