I work on a corporate laptop that has an infamous root CA certicate installed, which allows the company to intercept all my browser traffic and perform a MITM attack.

Ideally, I’d like to use the company laptop to read my own mail, access my NAS in my time off.

I fear that even if I configure containers on that laptop to run alpine + wireguard client + firefox, the traffic would still be decrypted. If so, could you explain how the wireguard handshake could be tampered with?

What about Tor in a container? Would that work or is that pointless as well?

Huge kudos if you also take the time to explain your answer.

    • ddh@lemmy.sdf.org
      link
      fedilink
      English
      arrow-up
      0
      ·
      8 months ago

      I’ve done this in the past without apparent issue. Could you perhaps expand on where the risks arise here? My impression was that unless there is some independent hardware running code separate from the OS, then it would be OK?

      • baritone_edge@lemmy.ml
        link
        fedilink
        arrow-up
        0
        ·
        8 months ago

        Not an expert, but I believe that the company could detect that it was booted to another OS and you could have trouble at work for policy violation. But this process would likely be ‘safe’ from a personal privacy/security perspective.

        • ddh@lemmy.sdf.org
          link
          fedilink
          English
          arrow-up
          0
          ·
          8 months ago

          Let’s assume it’s allowed. Obviously it’s untrusted hardware, but for widely issued corporate PCs, what’s the risk that there would be some hardware snooping going on if you controlled the OS?