this post was submitted on 22 Aug 2023
533 points (96.8% liked)

Privacy

32156 readers
916 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
 
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 1 points 1 year ago* (last edited 1 year ago)

https://www.cloudflare.com/learning/security/what-is-https-inspection/

https://blog.cloudflare.com/monsters-in-the-middleboxes/

While this has traditionally been achieved by having the end client install a new certificate into their device for the corporations certificate authority, Google and other security firms also offer network appliances that will do this using certificates your device already trusts such as the above Google Trust Services LLC certificate. I've also experienced this 4 years ago with connections intercepted using certs from DigiCert and I'm sure there are others out there.

Https is dependent on a chain of trust, but most end users no little to nothing about it and definitely don't chose which certificates to base that chain of trust on. Instead you're given a set of certificates from the os/software developers and told to trust everything that leads back to those without any idea who has the authority to sign with those certificates.

Theoretically speaking; I could have an insider at letsencrypt who bypasses their check to see if I actually control a particular domain and instead just issues every certificate for any domain I ask for. Your browser wouldn't know the difference, just accepting them as valid certs as they've got the domains you asked for and they're signed by someone the browser trusts.

Google and others sell exactly that service.