Live data from Hacker News

Ruin My Search History

ruinmysearchhistory.com

81–90 of 211 posts

Re: Ruin My Search History

#82
post #80

Earlier quoted context omitted.

They actually do delete.

How do you know this for a fact? If the roles were reversed would you delete? Or would you just like and say you did?

If I were representing a big, well known company with lots of money to give out in settlements, I'd be much more likely not to say anything than to bother lying.

Re: Ruin My Search History

#84

Earlier quoted context omitted.

Do companies really MITM SSL traffic in order to watch employees surfing habits?

You bet they do! In the past I have had to manually install my company's certificates as a root CA. The annoying thing was that the certs they use are expired and use SHA-1, so I also had to explicitly tell my browser to trust expired/unsafe certificates as well. All in the name of increased security!

I would quit a job like that, unless there were seriously profound reasons for such a grotesque invasion.

1. There are proper ways to restrict activity without resorting to eavesdropping.

2. If they don't trust you enough to be responsible and use good judgement, you're probably stuck in a dead-end situation anyway.

3. In the more rare scenarios, where you might be operating live-saving or life-threatening equipment, or handling the salaries of many people, and dealing with monentary quantities in the many millions of dollars, guess what? You probably shouldn't be using an ordinary computer, with a web browser connected to the internet to perform those sorts of tasks, within the same operating system environment as ordinary web surfing to begin with.

Re: Ruin My Search History

#86
post #80

Earlier quoted context omitted.

They actually do delete.

How do you know this for a fact? If the roles were reversed would you delete? Or would you just like and say you did?

If I were in charge of a publicly traded company I most definitely wouldn't want a scandal like that lurking beneath the surface. It would absolutely leak.

Re: Ruin My Search History

#89

Earlier quoted context omitted.

I mean, that's how I MITM SSL traffic on a daily basis to do development. None of that speaks to HSTS/Pinning... which is the feature meant to protect against this sort of thing. I'm specifically asking about how a company can bypass HSTS/Pinning without modifying my local browser. Everything I'm reading indicates that's not possible.

https://developer.mozilla.org/en-US/docs/Web/Security/Public... >Firefox (and Chrome) disable Pin Validation for Pinned Hosts whose validated certificate chain terminates at a user-defined trust anchor (rather than a built-in trust anchor). This means that for users who imported custom root certificates all pinning violations are ignored. That last sentence is key. From Wikipedia: some browsers "disable pinning for c…

What does that have to do with wifi certificates?
Post reply on HN