Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Notorious b.s.d.
Jan 25, 2003

by Reene

big scary monsters posted:

at a company in the US, probably, in europe, probably not

apparently it's not uncommon for web filter systems to even intercept https traffic using an internal ca

corporate networks usually man-in-the-middle ssl, yes

but they will whitelist sites to not be MITM'ed. your employer has zero interest in monitoring your interactions with your bank, for example.

Adbot
ADBOT LOVES YOU

big scary monsters
Sep 2, 2011

-~Skullwave~-

goddamnedtwisto posted:

on a corporate network in most of europe, it's absolutely legal, with varying degrees of spelling out to your employees that you're doing it

surely it'd fall foul of the DPD, especially if you're doing mitm on https. for example: it's my lunch break. i log in to my online banking on the company network and transfer some cash to my daughter. then i go on amazon and order a birthday present sent to her home address. finally i send her a tasteful jacquie lawsons e-card. now the company has processed and stored her personal information, without her knowledge or consent, and would seem to lack a specific and legitimate purpose for holding that information

unless you're doing very hands-off and minimally intrusive filtering/monitoring, i don't see how you could avoid a hundred scenarios like that happening every day. i admit that this is not an area i'm exactly clued up on, i'm just going off half-remembered training stuff, so i'd be interested in hearing it from someone who actually has a clue

NoneMoreNegative
Jul 20, 2000
GOTH FASCISTIC
PAIN
MASTER




shit wizard dad



muffled reeeeeeee

Notorious b.s.d.
Jan 25, 2003

by Reene

big scary monsters posted:

surely it'd fall foul of the DPD, especially if you're doing mitm on https. for example: it's my lunch break. i log in to my online banking on the company network and transfer some cash to my daughter. then i go on amazon and order a birthday present sent to her home address. finally i send her a tasteful jacquie lawsons e-card. now the company has processed and stored her personal information, without her knowledge or consent, and would seem to lack a specific and legitimate purpose for holding that information

the specific and legitimate purpose is monitoring employee activity

you, as an employee, are extensively and repeatedly informed that the company monitors your activity on corporate networks. you and you alone are responsible for violating your daughter's privacy.

(also, the bank's web site would probably be whitelisted, since the company has zero interest in snooping on your banking activity. but that's not important here.)

Shaggar
Apr 26, 2006
all traffic on your corporate network should be snooped for security reasons. do not do personal poo poo on company resources.

KoRMaK
Jul 31, 2012



ugh sounds like heck

Salt Fish
Sep 11, 2003

Cybernetic Crumb

big scary monsters posted:

surely it'd fall foul of the DPD, especially if you're doing mitm on https. for example: it's my lunch break. i log in to my online banking on the company network and transfer some cash to my daughter. then i go on amazon and order a birthday present sent to her home address. finally i send her a tasteful jacquie lawsons e-card. now the company has processed and stored her personal information, without her knowledge or consent, and would seem to lack a specific and legitimate purpose for holding that information

unless you're doing very hands-off and minimally intrusive filtering/monitoring, i don't see how you could avoid a hundred scenarios like that happening every day. i admit that this is not an area i'm exactly clued up on, i'm just going off half-remembered training stuff, so i'd be interested in hearing it from someone who actually has a clue

My dude have you heard of ssh tunneling?

Nitr0
Aug 17, 2005

IT'S FREE REAL ESTATE

Salt Fish posted:

My dude have you heard of ssh tunneling?

lol if you think a corp doing ssl mitm attacks isn't going to block or at least notice your goofy ssh tunnel

Trabant
Nov 26, 2011

All systems nominal.
https://twitter.com/K2PLANTHIRE/status/838675439971348480

Improbable Lobster
Jan 6, 2012

"From each according to his ability" said Ares. It sounded like a quotation.
Buglord

Notorious b.s.d.
Jan 25, 2003

by Reene

Salt Fish posted:

My dude have you heard of ssh tunneling?

ssh tunneling through a proxy only works if HTTP CONNECT is available and works correctly. which it never does in a mitm environment.

which is, of course, the point of the mitm.

they don't want you passing arbitrary things through the proxy

Silver Alicorn
Mar 30, 2008

𝓪 𝓻𝓮𝓭 𝓹𝓪𝓷𝓭𝓪 𝓲𝓼 𝓪 𝓬𝓾𝓻𝓲𝓸𝓾𝓼 𝓼𝓸𝓻𝓽 𝓸𝓯 𝓬𝓻𝓮𝓪𝓽𝓾𝓻𝓮

Improbable Lobster
Jan 6, 2012

"From each according to his ability" said Ares. It sounded like a quotation.
Buglord

KoRMaK
Jul 31, 2012



https://i.imgur.com/ChJwwZc.mp4

goddamnedtwisto
Dec 31, 2004

If you ask me about the mole people in the London Underground, I WILL be forced to kill you
Fun Shoe

big scary monsters posted:

surely it'd fall foul of the DPD, especially if you're doing mitm on https. for example: it's my lunch break. i log in to my online banking on the company network and transfer some cash to my daughter. then i go on amazon and order a birthday present sent to her home address. finally i send her a tasteful jacquie lawsons e-card. now the company has processed and stored her personal information, without her knowledge or consent, and would seem to lack a specific and legitimate purpose for holding that information

unless you're doing very hands-off and minimally intrusive filtering/monitoring, i don't see how you could avoid a hundred scenarios like that happening every day. i admit that this is not an area i'm exactly clued up on, i'm just going off half-remembered training stuff, so i'd be interested in hearing it from someone who actually has a clue

okay, answering just for the uk because my knowledge of eu law is much sketchier. a much simpler example is personal email accessed from a corporate ("private" in uk legal terms) network, which is perfectly legit for companies to capture as long as they do not process or transfer it for reasons otherwise forbidden by law. so it's perfectly legit for a company to capture all of your internet traffic, even decrypting it, as it transits their network, for the purposes of protecting their own network or commercial interests. so virus-scanning it or even searching it for evidence that you're stealing for the company is fine, using it to discover that you're pregnant and sack you before you have a chance to declare it (and get statutory protection) isn't.

there's a proportionality test - you can't hold everything indefinitely, and you can't intercept everything just to work out who keeps leaving the toilet seat up, and there's still a requirement to inform your users that you're doing it (and allow them to access all data you hold about them - and also anyone else with a court order or dpa/ripa authority), but the balance is very much towards the company.

even under eu law you're not legally entitled to your own ideas on company time, why would your email be any different?

jetz0r
May 10, 2003

Tomorrow, our nation will sit on the throne of the world. This is not a figment of the imagination, but a fact. Tomorrow we will lead the world, Allah willing.



i'm unironically happy that dickbutt and loss weren't taken by nazis

Babies Getting Rabies
Apr 21, 2007

Sugartime Jones

once upon a time i was falling in love

prefect
Sep 11, 2001

No one, Woodhouse.
No one.




Dead Man’s Band

Babies Getting Rabies posted:

once upon a time i was falling in love

:golfclap:

big scary monsters
Sep 2, 2011

-~Skullwave~-
thanks for the corporate monitoring replies better informed people



Video Nasty
Jun 17, 2003


lmao

 


 



 

prefect
Sep 11, 2001

No one, Woodhouse.
No one.




Dead Man’s Band

it's german; it means "the mart"

prefect
Sep 11, 2001

No one, Woodhouse.
No one.




Dead Man’s Band


earth is pretty awesome

KOTEX GOD OF BLOOD
Jul 7, 2012

https://www.youtube.com/watch?v=LKJ-0ZO4pxo

ThaGhettoJew
Jul 4, 2003

The world is a ghetto
Is the knife fight over? Because I know of a well-armed, deadly green beananimal.

crap nerd
May 24, 2008
https://twitter.com/Skateboard_Gifs/status/841000134498430977

prefect
Sep 11, 2001

No one, Woodhouse.
No one.




Dead Man’s Band

i was surprised and impressed

twice :monocle:

Video Nasty
Jun 17, 2003


oh gently caress



 

 

Inexplicable Humblebrag
Sep 20, 2003


i have no idea why that prompted such a full-on belly laugh

Kirk
Sep 22, 2003

Improbable Lobster
Jan 6, 2012

"From each according to his ability" said Ares. It sounded like a quotation.
Buglord
https://www.youtube.com/watch?v=ExOCc_bHj6U&hd=1

Improbable Lobster
Jan 6, 2012

"From each according to his ability" said Ares. It sounded like a quotation.
Buglord

vodkat
Jun 30, 2012



cannot legally be sold as vodka
http://i.imgur.com/1fVfzu6.mp4

akadajet
Sep 14, 2003

DOWN JACKET FETISH posted:

i have no idea why that prompted such a full-on belly laugh

the fact that there's a store called dick smith

spankmeister
Jun 15, 2008






akadajet posted:

the fact that there's a store called dick smith

:australia:

big scary monsters
Sep 2, 2011

-~Skullwave~-

lol

akadajet
Sep 14, 2003


champagne posting
Apr 5, 2006

YOU ARE A BRAIN
IN A BUNKER



I'm with the last poster: give me a suicide free laptop and OS

Salt Fish
Sep 11, 2003

Cybernetic Crumb

Nitr0 posted:

lol if you think a corp doing ssl mitm attacks isn't going to block or at least notice your goofy ssh tunnel


If my workstation didn't have multiple ssh tunnels open during working hours I'd probably get fired.

cinci zoo sniper
Mar 15, 2013




Adbot
ADBOT LOVES YOU

Inexplicable Humblebrag
Sep 20, 2003

Person of Interest circa the end of season 4 looking weird

  • Locked thread