Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The docs mention it can be bypassed for configured domains.


Yes, I read it. That means that it doesn’t work in those cases. Btw, as a developer it’s very easy to have something like that. It’s not as trivial as it seems at all. I encountered with similar problems all the time, with similar solutions (mainly for security theater reasons) in the past. There are websites which simply doesn’t work if you replace certificates, regardless of browser or CA for example.


Yes, I've worked with people who have run into issues with "security" solutions like ZScaler. I have tried it with some APIs (like GitHub) and it does work. Not to say it will work in your case.


I was just interested how it works, because above it was sold as “it works”, when in reality, “it works*”.


Isn't it that way with most software? "It works", except when it doesn't.


There is a difference between bugs/failures, and false advertisement. The solution used here has well known shortcomings.


All SSL/TLS interception has the shortcoming. In other contexts, that’s a good thing, when certificate pinning works, I mean.


microsandbox is designed to work with most security products. there's a dedicated section for this in the docs that makes this entire process seamless: https://docs.microsandbox.dev/networking/tls#trusting-host-c...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: