I am not a Mozilla developer, nor have I ever been, but I am a user of what I
consider to still be the free Internet.

I have been in scenarios with silent MITM attacks, primarily corporate
environments as has been mentioned on this thread, and I would _greatly_
appreciate visual indication that my communications are using certificates that
chain up to either a non-standard CA, or are not expected for any other reason.

I believe this will lead to the best experience for an end user: don't black
out my Internet, but do leave me with full information so that I can make an
informed decision either way.

Even on corporate hardware I would like at least a notification that this is
happening.

--
Wolf
_______________________________________________
dev-security-policy mailing list
dev-security-policy@lists.mozilla.org
https://lists.mozilla.org/listinfo/dev-security-policy
      • Re: Nation State... Wayne Thayer via dev-security-policy
        • Re: Nation S... Matthew Hardeman via dev-security-policy
          • Re: Nati... Andrew via dev-security-policy
            • Re:... Matthew Hardeman via dev-security-policy
              • ... gewalopdrbat--- via dev-security-policy
              • ... healthyelijah--- via dev-security-policy
              • ... Corey Bonnell via dev-security-policy
              • ... Matthew Hardeman via dev-security-policy
              • ... jfb1776--- via dev-security-policy
              • ... whateverusernameforme--- via dev-security-policy
            • Re:... wolfgang.richter--- via dev-security-policy
              • ... mucius--- via dev-security-policy
              • ... peridiane--- via dev-security-policy
              • ... Troy Cauble via dev-security-policy
              • ... Matthew Hardeman via dev-security-policy
              • ... bayden--- via dev-security-policy
              • ... Jakob Bohm via dev-security-policy
              • ... My1 via dev-security-policy
              • ... Jakob Bohm via dev-security-policy
          • Re: Nati... troycauble--- via dev-security-policy
  • Re: Nation State MITM CA'... cmalikz.h--- via dev-security-policy

Reply via email to