Originally Posted by
gfunkdave
3. Creation of a false certificate authority (and installation of that CA on your computer, which isn't hard in a corporate environment) that masquerades as gmail.com and proxies your traffic to the real gmail.com. Your computer thinks it's talking to Gmail but it's actually talking to CorporateServer. Your communication with Gmail is decrypted on CorporateServer, logged/examined, then re-encrypted and sent to the real Gmail.
There is a solution to this: Perspectives -
http://www.cs.cmu.edu/~perspectives/. It is available as Chrome and as Firefox extension:
https://chrome.google.com/webstore/d...fopejdpglpiahn
https://addons.mozilla.org/en-US/fir.../perspectives/