Untrusted connection warning on work pc

Soldato
Joined
2 Jun 2007
Posts
6,839
Location
Mornington Crescent
Just a little background first. At work we are allowed to use our computers as we like within reason. Everyone has windows 7 and accounts which let them install any software they like. Equally we are allowed to browse the net over lunch, and so on.

Today, Firefox has suddenly started reporting every https page I try to visit as being an untrusted connection. This even includes places like Google. Viewing the certificate that the site is apparently providing shows a certificate from Cyberoam SSL.

Doing a little search, this seems to be something which lists my company (or specifically their outsourced IT department to intercept all my traffic? This doesn't affect me too much, though I had been using my computer to check my bank account and emails which I think I will be stopping now.

Does anyone else know more about this service? Just curious as to how it works and what exactly it can allow.
 
Funny thing is, it's been installed in chrome, IE and Firefox, but Firefox was the only one that has gone 'Woah, what's going on here'. Checking the certs for Google in IE and chrome it shows Cyberoam.

Thanks for your help guys. Back to my phone for anything requiring a secure connection.
 
Why is it giving the untrusted warning, whats the reason it gives?

Is it that it doesn't trust the cyberoam cert (in which case they haven't installed it in the client browsers), or that the name on the cert doesn't match the domain visited?

The certificate is not trusted because the issuer certificate is not trusted.
Error code : sec_error_untrusted_issuer

Yes, as mentioned above I could speak with IT and they will fix whatever it is that it's causing the error (and indeed I will) , I'm just curious about what exactly it is they are trying to do and what they will be able to do/see with it.
 
When you say content, do you mean just the website I visit, or if I check my email for example would they be able to see the emails I'm reading? Ditto if I'm checking my bank statement?
 
Huh, just had a couple of people in the office come to me complaining they couldn't access the Internet properly on their tablets. Had a look, they are getting the untrusted certificate error as well, so looks like it's a blanket thing across the network.

Out of interest, since I'm the guy who knows about IT in the office, what should I tell them? If they allow the certificate then the company will be able to see everything they do in plaintext, which will include all their passwords and everything else that they do while on the work network?
 
Apparently it's just an anti virus measure since one of the machines in the office got infected, started sending out spam emails and got our domain blacklisted :o
Seems a little extreme, but there you go.
 
Back
Top Bottom