Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

There are lots of applications that use HTTPS under the covers that will break if certificate validation fails, so not having the root cert installed does "break" those devices.

(There are unfortunately even more apps that use HTTPS under the covers that appear not to care whether certs validate).



Sure, but that falls right into the category of "a problem for the employee". The traffic still gets MITMed, so the employer shouldn't care.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: