[cryptography] trustwave admits issuing corporate mitm certs

Steven Bellovin smb at cs.columbia.edu
Mon Feb 13 00:24:54 EST 2012


On Feb 12, 2012, at 10:26 46PM, Nico Williams wrote:

> On Sun, Feb 12, 2012 at 9:13 PM, Krassimir Tzvetanov
> <maillists at krassi.biz> wrote:
>> I agree, I'm just reflecting on the reality... :(
> 
> Reality is actually as I described, at least for some shops that I'm
> familiar with.
> 
The trend is the other way, towards allowing (and even encouraging)
employee-owned devices.  If nothing else, it saves the company money.
It also lets you get more work out of employees if they can deal
with management requests from their personal iToys or Andtoys.

The trick is to manage this behavior; banning it tends to be
futile.


		--Steve Bellovin, https://www.cs.columbia.edu/~smb








More information about the cryptography mailing list