Skip to content

Comment on One of the Most Alarming Internet Proposals I've Seen

Comments

There are some kinda legitimate uses for this in certain environments -- enterprise DLP, various kinds of filtering, etc. Potentially even caching and stuff on the distant end of really weird network connections (when I go to Mars in ~30y, I'd like to have as much cached as possible, and converted to message-based vs. connection-oriented protocols).

We have good enough workarounds for this right now (putting wildcard CA certs on devices and proxying that way), but they're not awesome. So, if there were a way to keep this from being used for evil, it could make some existing non-evil activities easier.

But, on balance, the risk of evil might be too high.

There are potentially legitimate (though still sketchy) reasons to MITM HTTPS traffic from a host configured to allow that (for instance, by trusting an organizational CA). There are no legitimate reasons to MITM HTTPS traffic without the host's knowledge.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.