• bokherif@lemmy.world
    link
    fedilink
    English
    arrow-up
    42
    ·
    2 个月前

    Right, like a router can unencrypt and read what’s on the link. This is just IP blocks which will never work lol.

    • Semperverus@lemmy.world
      link
      fedilink
      English
      arrow-up
      27
      arrow-down
      1
      ·
      2 个月前

      “Hey there customer, if you want internet access on our network (the only one available in your area), you have to install our intermediary certificate on your machine!”

        • Semperverus@lemmy.world
          link
          fedilink
          English
          arrow-up
          12
          ·
          2 个月前

          “Oh sorry, looks like we couldn’t decrypt that traffic, those packets went to the burn pile”

          • asdfasdfasdf@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            2 个月前

            How do they know what qualifies as “encrypted” vs a binary blob that could be a photo or something?

            • Semperverus@lemmy.world
              link
              fedilink
              English
              arrow-up
              1
              ·
              2 个月前

              File headers, magic bits, all sorts of stuff. Plus you can (and they do) try to load common file types, so if a PNG isn’t loading correctly, it fails the test.

      • exu@feditown.com
        link
        fedilink
        English
        arrow-up
        3
        ·
        2 个月前

        From having worked in an enterprise environment, there’s a chunk of websites that break when you intercept their SSL connection.

          • exu@feditown.com
            link
            fedilink
            English
            arrow-up
            2
            ·
            2 个月前

            Not really, because the client system is configured to go through the proxy. That proxy will connect to the website and do filtering on the unencrypted content because it is initiating the connection. Next it’ll re-encrypt everything with its own certificate and serve it to the client.

              • exu@feditown.com
                link
                fedilink
                English
                arrow-up
                1
                ·
                2 个月前

                Yes, but that’s what you would need to do and get if everyone had to install an intermediate cert.