Je pense que si le navigateur ne voit pas la supercherie, alors c'est que ton entreprise a usurpé l'indentité de certains sites, et une autorité de certification a validé cette usurpation. Et ça, ce n'est pas joli.
Ça me fait penser à une affaire il y a quelques années :
A French government agency has been caught signing SSL certificates and impersonating Google.
The bogus certificates were endorsed by the certificate authority of the French Treasury, DG Trésor. And the Treasury's own authorisation certificate was, in turn, vouched for by IGC/A (Infrastructure de Gestion de la Confiance de l'Administration) and ultimately ANSSI, the French equivalent of the CESG assurance wing of GCHQ.
It seems the French Treasury department created the counterfeit certificate in order to monitor employee traffic that would otherwise pass through its network wrapped in encryption. The dodgy certificate allowed man-in-the-middle SSL interception, a heavily frowned on practice that violates the trust model of internet security.
# usurpation
Posté par goeb . En réponse au journal Légalité de l'interception du flux SSL au sein d'une entreprise. Évalué à 1.
Je pense que si le navigateur ne voit pas la supercherie, alors c'est que ton entreprise a usurpé l'indentité de certains sites, et une autorité de certification a validé cette usurpation. Et ça, ce n'est pas joli.
Ça me fait penser à une affaire il y a quelques années :
https://www.theregister.co.uk/2013/12/10/french_gov_dodgy_ssl_cert_reprimand/
Extrait :