said by knightmb
:said by funchords
:The device is inserted in the middle, so it can see the entire transaction, including the cryptographic key exchange.
That said, I have no evidence that it decrypts https, and I personally believe that it would use precious CPU time in a middlebox where processing speed must be an issue.
We also have NebuAd's word that they won't try it, FWIW.
I have to agree, they wouldn't need to waste CPU time to do this. That would actually give it a dual purpose perhaps. Serve ads and secret wiretaps. Either way, we might not be able to do anything about the secret wiretap, but at least we can make the regular stuff all look like garbage. As usual in this type of stories, I chime in the link in my signature.
I think espaeth already answered the HTTPS issue here: