Warning: people should know this is NSFW for anyone with a company that monitors your web usage. I also wouldn't run this from an authoritarian country where local officials may not appreciate the joke.
Ruin My Search History
81–90 of 211 posts
Re: Ruin My Search History
#82Earlier quoted context omitted.
They actually do delete.
How do you know this for a fact? If the roles were reversed would you delete? Or would you just like and say you did?
Re: Ruin My Search History
#83Re: Ruin My Search History
#84Earlier quoted context omitted.
Do companies really MITM SSL traffic in order to watch employees surfing habits?
You bet they do! In the past I have had to manually install my company's certificates as a root CA. The annoying thing was that the certs they use are expired and use SHA-1, so I also had to explicitly tell my browser to trust expired/unsafe certificates as well. All in the name of increased security!
1. There are proper ways to restrict activity without resorting to eavesdropping.
2. If they don't trust you enough to be responsible and use good judgement, you're probably stuck in a dead-end situation anyway.
3. In the more rare scenarios, where you might be operating live-saving or life-threatening equipment, or handling the salaries of many people, and dealing with monentary quantities in the many millions of dollars, guess what? You probably shouldn't be using an ordinary computer, with a web browser connected to the internet to perform those sorts of tasks, within the same operating system environment as ordinary web surfing to begin with.
Re: Ruin My Search History
#85Re: Ruin My Search History
#86Earlier quoted context omitted.
They actually do delete.
How do you know this for a fact? If the roles were reversed would you delete? Or would you just like and say you did?
Re: Ruin My Search History
#87Re: Ruin My Search History
#88Re: Ruin My Search History
#89Earlier quoted context omitted.
I mean, that's how I MITM SSL traffic on a daily basis to do development. None of that speaks to HSTS/Pinning... which is the feature meant to protect against this sort of thing. I'm specifically asking about how a company can bypass HSTS/Pinning without modifying my local browser. Everything I'm reading indicates that's not possible.
https://developer.mozilla.org/en-US/docs/Web/Security/Public... >Firefox (and Chrome) disable Pin Validation for Pinned Hosts whose validated certificate chain terminates at a user-defined trust anchor (rather than a built-in trust anchor). This means that for users who imported custom root certificates all pinning violations are ignored. That last sentence is key. From Wikipedia: some browsers "disable pinning for c…
Re: Ruin My Search History
#90Next step is a chrome plugin that randomly searches for stuff in the background.