TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: Does your company intercept HTTPS? What are alternatives?

5 点作者 codesuki将近 6 年前
As the title says, I am curious whether this is usual and what are alternatives to HTTPS traffic interception to protect a company and for doing incident response & analysis.

5 条评论

BjoernKW将近 6 年前
I&#x27;ve worked for customers in the past who did this. For the most part it was a huge hassle and didn&#x27;t really help with incident response and analysis.<p>You have to install company root certificates on clients, perhaps even merely self-signed ones if they&#x27;ve been particularly cheap and lazy. Then traffic needs to be routed through a firewall &#x2F; proxy as well.<p>This in turn can lead to issues with tools such as Maven or NPM. These issues can be hard to debug.<p>Besides, if you don&#x27;t know what you&#x27;re doing - and most companies don&#x27;t specialise in network security - it&#x27;s easy to get the setup wrong and create major security problems.<p>Sometimes the motivation isn&#x27;t so much protection against malware but rather a petty desire to know what employees are doing.<p>For these reasons I&#x27;d strongly advise against this practice.<p>As for alternatives:<p>Follow and encourage the use of accepted best practices.<p>Educate and trust your employees about security.
Samon将近 6 年前
Yep, we have proxy servers with SSL decryption&#x2F;inspection. Root CA installed on all company devices.<p>There are a number of whitelisted URLs (banks, and services that refuse to work with a MITM&#x27;ed cert) but other than the initial headache during implementation, it is pretty seamless now.
dmlittle将近 6 年前
My current company doesn&#x27;t do this but I&#x27;m curious how it is supposed to help with incident response and analysis. Are you talking about server traffic or employee laptop&#x27;s traffic?
评论 #20631740 未加载
评论 #20632016 未加载
alltakendamned将近 6 年前
This is a terrible practice with major security and privacy impacts.<p>And easily defeated by certificate pinning.
yellow_lead将近 6 年前
Does this require installing a company cert?
评论 #20631999 未加载