I think this practice is harmful but there’s nothing I can do to stop.
I think this practice is harmful but there’s nothing I can do to stop.
Solution is simple- don’t use business machines for personal stuff[0] and there will be nothing to intercept.
[0] this is usually already mentioned in company computer use policy anyway.
If you don't like it then there is something you can do: go work somewhere else, or use your own device on your own network.
Moral requirements to protect patient info has absolutely nothing to do with MITM traffic to employee banking sessions, etc.
There’s very little empirical data showing benefit of this for data loss prevention or intrusion detection. What I’ve seen is security theater by companies who make money selling these products.
The other option I have, other than quitting, is to improve company policy to focus resources away from wasteful spending toward productive. As well as to try to influence browser vendors to block this. Fortunately if Chrome and Firefox go a step further and block this behavior for companies then it’s not practical for an organization to spend money to purchase a different browser. This is possible since Microsoft went to chromium.
Obviously, I can also use my own device.
Don't use employer devices for personal business.
If this was a real problem, traffic should just be blocked. Not snooped.
There’s quite a few ways to prevent this. Custom CAs are pretty necessary for internal networks so I don’t think they should be blocked whole cloth, but restricting how they can be used so they don’t impersonate real things would be nice.
It sounds like you want all domains to be divided into 2 categories: testing/internal domains, and real domains. Where in real domains only public CAs with valid CT entries would be trusted, but in testing domains custom CAs are allowed. Maybe we could go even a step further in the division and disallow public CAs from testing domains. There's of course the question of how to distinguish a real donation from a testing domain; maybe this could be done by saying all testing domains must be in a special TLD such as .local or .testing .
This might work, but it it's still restricting developers, because if they need to debug some problem they have less options on how to do it. There might be a problem with cookies on the real domain that won't reproduce on the testing domain. And they need to maintain 2 server configs instead of 1, 1 for each domain.
My complaint isn’t about privacy, it’s about efficiency.