I also wouldn't run this from an authoritarian country where local officials may not appreciate the joke.
I also wouldn't run this from an authoritarian country where local officials may not appreciate the joke.
1. There are proper ways to restrict activity without resorting to eavesdropping.
2. If they don't trust you enough to be responsible and use good judgement, you're probably stuck in a dead-end situation anyway.
3. In the more rare scenarios, where you might be operating live-saving or life-threatening equipment, or handling the salaries of many people, and dealing with monentary quantities in the many millions of dollars, guess what? You probably shouldn't be using an ordinary computer, with a web browser connected to the internet to perform those sorts of tasks, within the same operating system environment as ordinary web surfing to begin with.
Call centers, data entry, tier one support.
And I can't quite parse your sentence to know if you're implying that all companies do... (or just that I shouldn't be so naive as to assume none are), but I can see the cert chain for google.com in my browser at ${big_company} and it doesn't seem like I'm being MITM'd.
So again, how could I be MITM'd without being aware of it, given HSTS?
Yes, someone could have snuck in a hacked copy of Chrome Canary that exposes phony cert chain information... but that's not what we were talking about, and I don't think most IT departments have the sophistication required to pull that off.
http://security.stackexchange.com/a/2920
(Note: MITM is just one way companies monitor employees, but by no means the only way. If your company provided your work computer to you, or if they installed anything on your BYOD computer, I would treat everything you do on that computer as cc'ed to your boss by default.)
None of that speaks to HSTS/Pinning... which is the feature meant to protect against this sort of thing. I'm specifically asking about how a company can bypass HSTS/Pinning without modifying my local browser.
Everything I'm reading indicates that's not possible.
>Firefox (and Chrome) disable Pin Validation for Pinned Hosts whose validated certificate chain terminates at a user-defined trust anchor (rather than a built-in trust anchor). This means that for users who imported custom root certificates all pinning violations are ignored.
That last sentence is key. From Wikipedia: some browsers "disable pinning for certificate chains with private root certificates to enable various corporate content inspection scanners and web debugging tools. The RFC 7469 standard also recommends disabling pinning violation reports for such certificate chains."
(all this for Windows, I believe the same is true for OS X, Linux depends on your specific your setup)
Internet Properties -> Content -> Certificates -> Advanced
Certificate pinning, on the other hand, allows a client to refuse to connect to a TLS service that fails to prevent the correct certificate. This is generally a win, however it still doesn't give you what you want.
Firefox and Chromium (including Chrome) browsers will only validate certificate pins if the presented certificate is a public trust anchor (in otherwords, the certificates deployed by the operating system). If the certificate chains to a private trust anchor (a certificate installed by your admin), Firefox and Chromium based browsers will smile, wink, and play along.
So, yes, in theory these technologies could protect you, but the vendors that implemented Public Key Pinning opted to support the enterprise use case instead of protecting users.
That's the enterprise life
So yup this happens. Is it effective though? No, this took me 15 minutes and I wasn't even an employee with months if not years of time on their hands.
All the more reason to do it IMHO :)