Ask Slashdot: What's Your Take On HTTPS Snooping?
First time accepted submitter jez9999 writes "I recently worked for a relatively large company that imposed so-called transparent HTTPS proxying on their network. In practice, what this means is that they allow you to use HTTPS through their network, but it must be proxied through their server and their server must be trusted as a root CA. They were using the Cisco IronPort device to do this. The "transparency" seems to come from the fact that they tend to install their root CA into Internet Explorer's certificate store, so IE won't actually warn you that your HTTPS traffic may be being snooped on (nor will any other browser that uses IE's cert store, like Chrome). Is this a reasonable policy? Is it worth leaving a job over? Should it even be legal? It seems to me rather mad to go to huge effort to create a secure channel of communication for important data like online banking, transactions, and passwords, and then to just effectively hand over the keys to your employer. Or am I overreacting?"
Chances are they will whitelist any sites that may contain personally identifiable information such as banking sites etc. Most places do not want to get into privacy issues like this. Anything else is fair game. Personal e-mail might be a different story, but then again, in some verticals like finanicials, you should not be accessing personal e-mail anyway, per policy of most financial houses. Personal e-mail and the like are avenues for information to easily leave the firm.
I think that this may well be illegal, because even if you consent, the server at the other side of the connection hasn't consented. That means that at least one party to the communication is having their encrypted data intercepted and decrypted by a third party without their knowledge or consent. Wiretap laws apply to both communicating parties. Not aware of any case law, someone needs to actually Sue cisco bluecoat or one of the other ssl intercepting proxy makers to establish legality.
Because work keeps expanding to take up personal time, it's the only way for employees to claw some of it back.
Workplace climates are already going downhill faster and faster.
Please don't get me wrong, I am not supporting asshole companies sucking the life out of employees by paying them less and less, expecting more and more sacrifices, all while siphoning the money away for rich, useless, fucking wastes of space that are the upper executives in most very large companies. Boy have I known some.....
You should be able to have a balanced life and not need to conduct personal affairs at work.
As the CTO, I need to balance so many things. In this instance all I am trying to balance is security versus usability. I need to take very strong measures to prevent data leakage and be aware of it at least after the fact.
That's why I offer paths of least resistance. It's about the wisest thing I do, or at least I think I do. Personally, I don't care what you do at your desk. It's your responsibility to get your tasks done in the time allotted. All I want is for you to not destroy the company while you goof off, and sometimes goofing off for a minute or two can increase productivity and morale (my opinion). In any case, not my job to be the warden.
Normal people lack the sophistication to truly understand, and avoid, the dangers in the world we live in as far as technology is concerned. Hence, the path of least resistance. I make them use their own devices and prevent them from being able to connect to company equipment. Super glu in the USB socket is very effective, but so is disabling it in the OS, which allows them to still use it to charge stuff.
As far as spare time and unpaid work (there should never be such a thing), that is unfortunately not possible with some industries. I simply cannot allow regular employees to take work home, or have unfettered remote access. Some executives have it, because it is not possible to deny them, but it is very vulnerable. I have already had to chastise somebody for using company equipment for porn. Thankfully, I had support from higher up.
I have to be this vigilant. Failure on my part can mean tens of thousand of customers (possibly much higher) hurt because of loss of data. Worse, if it is private and sensitive medical records. I would hope that the CTO of any other company was protecting my data just as well.
LOL. We're not injecting anything.
We've got a Microsoft Enterprise PKI.
Our own Root CA, Policy CA, and Issuing CA.
All of the machines that are joined to our domain are company-owned workstations and servers.
The Local & Personal Certificate Stores are controlled through Group Policy.
All of our workstations have our internal root certificate already on the machines, and all of our workstations and servers explicitly trust our root certificate.
Again: Our stuff. Our network. Our data. You have no privacy.
If employees stopped conducting themselves like they thought they had privacy while they were surfing the net while they were at work they wouldn't be so shocked and amazed when they find out they have none.
> Many employers have figured out how to intercept HTTPS connections and decode their content.
>If you don't want your employer knowing all your secret information, such as account numbers, login ids, passwords, etc., you should never type any of these things on a work machine.
Or employers should be following the Electronic Data Rights and Privacy Acts, which prohibit them from viewing or using such information?
sigh... *whoosh!* There goes the point, right over your head. Let me try yet again.
By taking deliberate measures to thwart browsers from popping up warnings that an encrypted communications channel is compromised, companies that use transparent SSL interception techniques are misrepresenting to you that you are on a secure communications channel when in effect you are not.
Or put another way, it's settled law that the company owns all equipment in its buildings, rooms, cameras, etc, at least in the USA. Yet if they install said cameras secretly in the restroom, they can and have been successfully sued for breach of privacy. Your employer does not have unmitigated rights to monitor you. If you're using an open communication channel, that's one thing. But if they are misrepresenting a secured channel (i.e. an HTTPS connection) to you when they are actually spying on you, that's and entirely different matter.
Argue the "no expectation of privacy" argument all you want, but the HTTPS protocol carries an inherent expectation of privacy. If it didn't, banks and other financial institutions wouldn't use it, duh. Taking steps to transparently thwart it is the technological equivalent of installing cameras in a restroom.
And no, it is not settled law, unless you can point to cases that have been fought about SSL interception.
Two words for the non-smoker: Cigarette Break
Two words for anyone: Think Break. "I need a few minutes to study these drawings and specs uninterrupted. I'll be back in thirty." Then head for Starbucks, taking your personal laptop (or whatever). With all the noise and kafuffle and goofing off and bosses or cow-orkers sticking their noses in all the time in a cubicle farm, this is a necessary part of getting anything done.
Don't you dare tell me "that's not working." Better yet, write it on a yellow sticky, then just leave. And stretch it out to forty-five, at least.
Of course, this assumes you can turn in results, and not just goof off.
"Tongue tied and twisted, just an Earth bound misfit
Because it would be against the *law*. And their policy obviously state that breaches of the law are to be reported to the police.
Stefan Axelsson