In a corporate environment, if I can manipulate which certs are trusted and untrusted then I deserve to know if you're using Bluecoat. Even if I have to un-blacklist it again to make the web work.
And in the mean time, all kinds of people who *aren't* on corporate networks on corporate hardware should know if someone is paying a notorious internet spying company to spy on them.
But yes, CAs and TLS trusting are fundamentally broken.
(no subject)
Date: 2016-05-30 03:57 pm (UTC)And in the mean time, all kinds of people who *aren't* on corporate networks on corporate hardware should know if someone is paying a notorious internet spying company to spy on them.
But yes, CAs and TLS trusting are fundamentally broken.