The comfort in this article is knowing for every boutique german headphone company that insists on becoming a CA, there are thousands of nameless chinese companies producing superior products at lower prices that do to some measure respect the users privacy in that they arent more than just a USB peripheral. Sades and Xiberia for example make perfectly useful (if not a little bit cyberpunk) headsets that just operate…
Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks
41–50 of 123 posts
Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks
#42The comfort in this article is knowing for every boutique german headphone company that insists on becoming a CA, there are thousands of nameless chinese companies producing superior products at lower prices that do to some measure respect the users privacy in that they arent more than just a USB peripheral. Sades and Xiberia for example make perfectly useful (if not a little bit cyberpunk) headsets that just operate…
Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks
#43Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks
#44Earlier quoted context omitted.
the problem is not that they add a root ca to the store. the problem is that they use the same Root CA on every computer in the world AND adding it into the Store AND having the Root CA PRIVATE KEY on ANY computer.
> the problem is not that they add a root ca to the store. Yes there is. There is no valid reason for a glorified headphone driver to mess with what website your browser trusts.
Ideally browsers should implement well standardized, secure APIs for all devices in the world, but we are far from there. Until browser vendors implement the API you need, the only option is to employ this trick.
Of course, companies should NOT reuse the same certificate between installations though (just generate a certificate during the installation process and life is good again).
Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks
#45Earlier quoted context omitted.
I run some services for my private use. It's crazy that I need to have them certified by some third-party over-seas CA since I can't get my own devices to trust my own certificates. We're not at that point yet, but running your own trust root is getting quite annoying. For example, Android constantly nags about "network might be monitored" when custom certificates are installed.
> Android constantly nags about "network might be monitored" when custom certificates are installed. This is why I baked my home network certificate into the system trust store when building the ROM.
Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks
#46Earlier quoted context omitted.
In practice the corporation "dictating" the set of publicly trusted CA roots is the Mozilla Foundation, a 501(c)(3) non-profit with a large volunteer effort. On paper all the major browser vendors / operating system vendors (Microsoft, Apple, Google, Mozilla) have independent root trust programmes. But after several years working on this stuff I would say that all real public oversight is done by Mozilla, which AFAIC…
> In practice the "corporation" "dictating" the set of publicly trusted CA roots is the Mozilla Foundation, a 501(c)(3) non-profit with a large volunteer effort. Why the scare quotes on “corporation”? Mozilla Foundation is a corporation. Here are he articles of incorporation: https://www-archive.mozilla.org/foundation/documents/mf-arti...
Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks
#47All the technical mistakes aside, yet another illustration of why I refuse to use wireless peripherals. They're uniformly shoddy at best, dropping connections or having difficulty pairing often. The idea that headphones should need software strikes me as insane.
Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks
#48The comfort in this article is knowing for every boutique german headphone company that insists on becoming a CA, there are thousands of nameless chinese companies producing superior products at lower prices that do to some measure respect the users privacy in that they arent more than just a USB peripheral. Sades and Xiberia for example make perfectly useful (if not a little bit cyberpunk) headsets that just operate…
I was under the impression their maybe one of the biggest and most prominent headphone manufacturers in the world, especially when measured by R&D.
Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks
#49Earlier quoted context omitted.
As someone that has been burned by self signed internal only sites. Take the extra 15 minutes and get a proper cert, and domain name for your internal sites. It can save a massive amount of pain later.
burned how exactly?
We saved probably $100 and 2 hours by rolling our own solutions instead of doing things the standard way. It took weeks to clean the mess completely up.
Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks
#50All the technical mistakes aside, yet another illustration of why I refuse to use wireless peripherals. They're uniformly shoddy at best, dropping connections or having difficulty pairing often. The idea that headphones should need software strikes me as insane.
This is why Apple’s AirPods have been so popular. They really work quite well, compared to any other wireless headphones I’ve used. Easier pairing and better connections.