Speaking of which, what is the legality of your corporation injecting fake SSL certificates for sites served over HTTPS?