Their certs may be pinned, but from what I can tell there's nothing keeping me from introducing a new root cert to my system (IIRC there was a scary popup and that's it).
Here's a screenshot of Chrome giving me the "insecure" padlock, but still rendering Facebook while I debug the HTTPS traffic: http://puu.sh/jdGhc/128d35f793.png
Here's similar, showing Google HTTPS traffic being debugged while browsing in Safari (with nothing appearing out of the ordinary): http://puu.sh/jdGoW/3163db1e54.png
(the debugging proxy is Cellist, which I find to be a suitable replacement for mitmproxy, as long as I don't need rewrite/replay)
> if you can trick someone into running an EXE, it's game over
I suppose it is roughly equivalent (i.e. if you could get them to download a cert, you could probably get them to download an EXE so the point may be moot). I always figured you might have more luck with this sort of thing if you owned a Starbucks router or something, where people might be more accepting of having to jump through hoops to use the internet.
Here's a screenshot of Chrome giving me the "insecure" padlock, but still rendering Facebook while I debug the HTTPS traffic: http://puu.sh/jdGhc/128d35f793.png
Here's similar, showing Google HTTPS traffic being debugged while browsing in Safari (with nothing appearing out of the ordinary): http://puu.sh/jdGoW/3163db1e54.png
(the debugging proxy is Cellist, which I find to be a suitable replacement for mitmproxy, as long as I don't need rewrite/replay)
> if you can trick someone into running an EXE, it's game over
I suppose it is roughly equivalent (i.e. if you could get them to download a cert, you could probably get them to download an EXE so the point may be moot). I always figured you might have more luck with this sort of thing if you owned a Starbucks router or something, where people might be more accepting of having to jump through hoops to use the internet.