Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks
bleepingcomputer.com
Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks
1–10 of 123 posts
Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks
#2This kind of stuff shouldn't even be legal.
Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks
#3This is shocking behaviour. What's the difference between this and malicious software.
Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks
#4> the software was also installing a root certificate into the Trusted Root CA Certificate store. This kind of stuff shouldn't even be legal.
I could understand it if it was a small company doing so at the time when certificates were expensive, but Sennheiser has plenty of money and certificates can be obtained for free nowadays.
Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks
#5> the software was also installing a root certificate into the Trusted Root CA Certificate store. This kind of stuff shouldn't even be legal.
As a bit of a layman, is there even any legitimate reason at all (other than a user installing it in their own machine for reverse engineering purposes) for anyone to install a root certificate anymore? I could understand it if it was a small company doing so at the time when certificates were expensive, but Sennheiser has plenty of money and certificates can be obtained for free nowadays.
Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks
#6> the software was also installing a root certificate into the Trusted Root CA Certificate store. This kind of stuff shouldn't even be legal.
As a bit of a layman, is there even any legitimate reason at all (other than a user installing it in their own machine for reverse engineering purposes) for anyone to install a root certificate anymore? I could understand it if it was a small company doing so at the time when certificates were expensive, but Sennheiser has plenty of money and certificates can be obtained for free nowadays.
It's incredibly shady to have random software install into your trust store.
Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks
#7> the software was also installing a root certificate into the Trusted Root CA Certificate store. This kind of stuff shouldn't even be legal.
As a bit of a layman, is there even any legitimate reason at all (other than a user installing it in their own machine for reverse engineering purposes) for anyone to install a root certificate anymore? I could understand it if it was a small company doing so at the time when certificates were expensive, but Sennheiser has plenty of money and certificates can be obtained for free nowadays.
We're not at that point yet, but running your own trust root is getting quite annoying. For example, Android constantly nags about "network might be monitored" when custom certificates are installed.
Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks
#8Earlier quoted context omitted.
As a bit of a layman, is there even any legitimate reason at all (other than a user installing it in their own machine for reverse engineering purposes) for anyone to install a root certificate anymore? I could understand it if it was a small company doing so at the time when certificates were expensive, but Sennheiser has plenty of money and certificates can be obtained for free nowadays.
I run some services for my private use. It's crazy that I need to have them certified by some third-party over-seas CA since I can't get my own devices to trust my own certificates. We're not at that point yet, but running your own trust root is getting quite annoying. For example, Android constantly nags about "network might be monitored" when custom certificates are installed.
This is why I baked my home network certificate into the system trust store when building the ROM.
Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks
#9I feel glad I left for the mild shores of Linux in the early 00s.
Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks
#10> the software was also installing a root certificate into the Trusted Root CA Certificate store. This kind of stuff shouldn't even be legal.