• Brkdncr@lemmy.world
    link
    fedilink
    English
    arrow-up
    13
    ·
    17 hours ago

    You’re sure they aren’t decrypting your traffic? Check the root cert of any site and see if it’s their own root.

    • fonix232@fedia.io
      link
      fedilink
      arrow-up
      2
      ·
      7 hours ago

      Yep, they’re not decrypting HTTPS, I’ve triple checked. But we do have an MDM forced proxy service that does check any non-encrypted traffic…

    • dan@upvote.au
      link
      fedilink
      English
      arrow-up
      6
      ·
      edit-2
      13 hours ago

      Larger companies that monitor for corporate passwords being entered on third-party sites usually use a browser extension that’s force-installed using Chrome Enterprise. That’s especially the case if they mandate the usage of Chrome.

          • ShellMonkey@piefed.socdojo.com
            link
            fedilink
            English
            arrow-up
            2
            ·
            10 hours ago

            HSTS says it must be encrypted but a proxy will create two connections and look at it clear in the middle. On the other hand cert pinning says it must be a specific cert that breaks the site if decryption is used. Apple is big on doing that for a lot of their site and apps.