BananaBaconFries

BananaBaconFries t1_iy7usbj wrote

You should only be concerned if the certificate is used for decryption (as i mentioned),

But let's assume that it is; UNLESS you're using a VPN Software provided by your IT (which basically routes your traffic to them) you shouldn't be concerned about it.

A lot of managed devices enforces VPN connectivity to the company's network thus allowing inspection. We can even implement enforced VPN connectivity in which your computer CANT connect to the internet if you somehow turn off your VPN to your company ((despite your WiFi having no issues)

TL'DR;

  1. if youre using mobile data with no VPN Software provided by your company - they wont be able to see your traffic
  2. If youre using mobile data WITH VPN software running provided by your company - then LIKELY they are seeing your traffic; ((even without decryption; your DNS queries are quite visible so they know which websites you go to at least))
2

BananaBaconFries t1_iy3yt90 wrote

I dont understand speak german(?)But common reasons why certificates are installed on a computer, mobile device etc. is to skip the certificate error a user encounters or allows the device to "present" itself to a network device when attempting to use it; such use cases are:

  1. Decryption: They are inspecting your traffic; like the actual data(payload); many security products do this. This allows these said products to be inspect/protect you. HOWEVER, highlighting this allows your school to see your data. (this is actually a MiTM(Man in the Middle Attack) if it was not coming from a trusted source
  2. Authentication: Certificate-based client authentication; could be used for RADIUS or client authentication

I'm also reading that it is unsigned? This is actually normal; these tend to be self-signed certificates (SSC). Since basically you are trusting a Root CA Certificate ((this is whole another level of discussion which I wont get into detail to)).

Considering I can see the word WLAN in there; it's likely used for Authentication i.e., allow you to connect to your schools WiFi ; could be using EAP-TLS since they are using certificates.

-Source: Working as a Systems Engineer specializing on these stuff

-Recommendation: Just take note you've installed said certificate; dont forget to delete it after like your term end there at your school. Also install it on devices you actually use for school. e.g., if you just want to connect your phone to get free internet and not use it to access school resources; then dont do it

EDIT: I am assuming your iphone is school owned, like you work at that school? If this is a personal device; tbh I would not install it, trusting a certificate is a major consideration when installing it in a personal device and is honestly a breach of your own personal privacy (especially considering your school IT likely did not tell you what its purpose is since you asked it here in this reddit)

276

BananaBaconFries t1_ixktz99 wrote

I guess tshoot steps I would do is

  1. Make sure Find My Feature is ON and location is allowed for the app with precise location enabled
  2. Double check my privacy location settings; find my iphone should be enabled
  3. Make sure bluetooth is ON(BLUE) or at least semi-on(Grey). Do not completely disable it in settings
  4. Worse case, I would forget and re-pair my devices
8