Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The cache/proxy just needs to install its root certificate into your system store and no changes to the browser would be necessary.


It's not sufficient due to certificate pinning, and it also completely short-circuits any browser-based security policies keyed on the certificate or options advertised in the protocol like SPDY. That would be the worst possible outcome, and why any correct solution (i.e doesn't break security or functionality) would be hard to reach


Local root certificates are prioritized by all browsers over certificate pinning, for exactly such intentional MITM.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: