I work on a corporate laptop that has an infamous root CA certicate installed, which allows the company to intercept all my browser traffic and perform a MITM attack.
Ideally, I'd like to use the company laptop to read my own mail, access my NAS in my time off.
I fear that even if I configure containers on that laptop to run alpine + wireguard client + firefox, the traffic would still be decrypted. If so, could you explain how the wireguard handshake could be tampered with?
What about Tor in a container? Would that work or is that pointless as well?
Huge kudos if you also take the time to explain your answer.
You wouldn't do this with a stranger's device, so why insist you do it with your employer's device? Just don't.
If you have a workstation and want to use the same monitors/headsets/peripherals with both the company device and your personal device try one or two KVM switches.
Don’t. And beyond that if you use their WiFi, connect to a VPN. Best just use LTE.
If you want to use the same physical device just put Linux on a bootable USB stick and boot off that
If it boots from USB, boot a different OS. But overall, preferrably use a different device.