Tom appears to have totally missed SSLStrip. Before browsers screamed bloody murder over http, a MITM could defeat SSL by acting as the SSL endpoint and forwarding everything as plain http. And back then, the only indication was lack of a 16px lock icon and a missing "s" in "https". It's additionally daft to think that just because the page is public knowledge, a specific person reading the page is never sensitive in…
Privacy and security are not synonymous. Though it would have been nice to have the ideas discussed in the video.
While the title may be misleading, this is an excellent discussion of the security problems of HTTPS. Of his complaints about misguided security, this one has resonated the most with my experience: "Regarding my new enemy, ... • The absolute shits that have locked down corporate computers with the assumption that the user can’t have a legitimate reason to change settings on it, put in a USB stick, use the command lin…
Here's the thing. Now you're putting wear and tear, no matter how slight, on your device, you aren't being compensated for. Furthermore, you're opening yourself to legal exposure where your drives and data could be seized under reasonable suspicion you might have something on an unauthorized device. I make an ultimatum to people who employ me. You get me a workstation. You give me admin, you put your MDM or whatever on it, and you let me do what I need, and it gets back to you on cessation of employment unless they decide to sell/gift it to me as an acknowledgement of deprecation/whatever. Do not cross the streams. They employed you, not the other way around.