HTTPS redirects to HTTP for monitoring

John Levine johnl at iecc.com
Sun Jan 18 18:15:09 UTC 2015


>> So your idea is to block every HTTPS website?
>From my point of view, it is better than violate user privacy & safety.
>
>Sneaky is evil.

I expect your users would fire you when they found you'd blocked access to Google.

>>> These boxes that violate end to end encryption are a great place for
>>> hackers to steal the bank and identity info of everyone in your company.

Since the end user machines are generally running Windows, why would bad guys
waste time on a much harder and more obscure target?




More information about the NANOG mailing list