Live data from Hacker News

Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks

bleepingcomputer.com

41–50 of 123 posts

Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks

#41
post #33

The comfort in this article is knowing for every boutique german headphone company that insists on becoming a CA, there are thousands of nameless chinese companies producing superior products at lower prices that do to some measure respect the users privacy in that they arent more than just a USB peripheral. Sades and Xiberia for example make perfectly useful (if not a little bit cyberpunk) headsets that just operate…

For the record chinesse products are championing this kid of issues, many times for malign reasons(not by mistake). Remember Lenovo?

Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks

#42
post #33

The comfort in this article is knowing for every boutique german headphone company that insists on becoming a CA, there are thousands of nameless chinese companies producing superior products at lower prices that do to some measure respect the users privacy in that they arent more than just a USB peripheral. Sades and Xiberia for example make perfectly useful (if not a little bit cyberpunk) headsets that just operate…

Nameless Chinese companies' software support is usually rather limited, to say the least. From the absence of firmware updates to the very basic set of the software features. When they will produce comparable software support for their hardware, there will be the same problems, maybe much worse.

Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks

#43
All the technical mistakes aside, yet another illustration of why I refuse to use wireless peripherals. They're uniformly shoddy at best, dropping connections or having difficulty pairing often. The idea that headphones should need software strikes me as insane.

Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks

#44
post #22
post #15

Earlier quoted context omitted.

the problem is not that they add a root ca to the store. the problem is that they use the same Root CA on every computer in the world AND adding it into the Store AND having the Root CA PRIVATE KEY on ANY computer.

> the problem is not that they add a root ca to the store. Yes there is. There is no valid reason for a glorified headphone driver to mess with what website your browser trusts.

There is a valid reason: to enable website-to-hardware communication (i.e, to provide a javascript-based api for websites to interface with that hardware).

Ideally browsers should implement well standardized, secure APIs for all devices in the world, but we are far from there. Until browser vendors implement the API you need, the only option is to employ this trick.

Of course, companies should NOT reuse the same certificate between installations though (just generate a certificate during the installation process and life is good again).

Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks

#45
post #7

Earlier quoted context omitted.

I run some services for my private use. It's crazy that I need to have them certified by some third-party over-seas CA since I can't get my own devices to trust my own certificates. We're not at that point yet, but running your own trust root is getting quite annoying. For example, Android constantly nags about "network might be monitored" when custom certificates are installed.

> Android constantly nags about "network might be monitored" when custom certificates are installed. This is why I baked my home network certificate into the system trust store when building the ROM.

What tools / guide did you use to accomplish this (building the ROM AND adding your certificate) ?

Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks

#46

Earlier quoted context omitted.

In practice the corporation "dictating" the set of publicly trusted CA roots is the Mozilla Foundation, a 501(c)(3) non-profit with a large volunteer effort. On paper all the major browser vendors / operating system vendors (Microsoft, Apple, Google, Mozilla) have independent root trust programmes. But after several years working on this stuff I would say that all real public oversight is done by Mozilla, which AFAIC…

> In practice the "corporation" "dictating" the set of publicly trusted CA roots is the Mozilla Foundation, a 501(c)(3) non-profit with a large volunteer effort. Why the scare quotes on “corporation”? Mozilla Foundation is a corporation. Here are he articles of incorporation: https://www-archive.mozilla.org/foundation/documents/mf-arti...

Fair. I've corrected my text to remove the scare quotes.

Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks

#47
post #43

All the technical mistakes aside, yet another illustration of why I refuse to use wireless peripherals. They're uniformly shoddy at best, dropping connections or having difficulty pairing often. The idea that headphones should need software strikes me as insane.

This is why Apple’s AirPods have been so popular. They really work quite well, compared to any other wireless headphones I’ve used. Easier pairing and better connections.

Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks

#48
post #33

The comfort in this article is knowing for every boutique german headphone company that insists on becoming a CA, there are thousands of nameless chinese companies producing superior products at lower prices that do to some measure respect the users privacy in that they arent more than just a USB peripheral. Sades and Xiberia for example make perfectly useful (if not a little bit cyberpunk) headsets that just operate…

I know this is really nitpicky, but is Sennheiser really a "boutique" company?

I was under the impression their maybe one of the biggest and most prominent headphone manufacturers in the world, especially when measured by R&D.

Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks

#49
post #13

Earlier quoted context omitted.

As someone that has been burned by self signed internal only sites. Take the extra 15 minutes and get a proper cert, and domain name for your internal sites. It can save a massive amount of pain later.

burned how exactly?

In this case we started doing hybrid cloud, we were unable to address a ton of sites since they were on a made up internal only tld. Plus every thing we could address served up certs we couldn’t trust since we were utilizing services that didn’t allow us to modify the trusted root cert store.

We saved probably $100 and 2 hours by rolling our own solutions instead of doing things the standard way. It took weeks to clean the mess completely up.

Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks

#50
post #47
post #43

All the technical mistakes aside, yet another illustration of why I refuse to use wireless peripherals. They're uniformly shoddy at best, dropping connections or having difficulty pairing often. The idea that headphones should need software strikes me as insane.

This is why Apple’s AirPods have been so popular. They really work quite well, compared to any other wireless headphones I’ve used. Easier pairing and better connections.

Also, surprisingly durable. Around April I accidentally left them out of their charger and outside in the pocket of a foldable chair when I went out of town for 1 month. It rained on them multiple times. When I found them I was sure they would be broken.. I charged them up and I still use them daily. No issues.
Post reply on HN