Viewing a single comment thread. View all comments

BananaBaconFries t1_iy7usbj wrote

You should only be concerned if the certificate is used for decryption (as i mentioned),

But let's assume that it is; UNLESS you're using a VPN Software provided by your IT (which basically routes your traffic to them) you shouldn't be concerned about it.

A lot of managed devices enforces VPN connectivity to the company's network thus allowing inspection. We can even implement enforced VPN connectivity in which your computer CANT connect to the internet if you somehow turn off your VPN to your company ((despite your WiFi having no issues)

TL'DR;

  1. if youre using mobile data with no VPN Software provided by your company - they wont be able to see your traffic
  2. If youre using mobile data WITH VPN software running provided by your company - then LIKELY they are seeing your traffic; ((even without decryption; your DNS queries are quite visible so they know which websites you go to at least))
2