Have any hardware companies ever written good accompanying software? From all the custom-ui graphics card config nonsense to utilities that phone home of their own accord, to things like this which are laughably awful. I feel glad I left for the mild shores of Linux in the early 00s.
Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks
91–100 of 123 posts
Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks
#92Have any hardware companies ever written good accompanying software? From all the custom-ui graphics card config nonsense to utilities that phone home of their own accord, to things like this which are laughably awful. I feel glad I left for the mild shores of Linux in the early 00s.
Apple?
Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks
#93> the software was also installing a root certificate into the Trusted Root CA Certificate store. This kind of stuff shouldn't even be legal.
I have to STRONGLY disagree. It's a slippery slope towards a world in which the computers we use are completely locked down and we have no control over what they trust, being dictated by the corporations and their interests. The freedom to modify your roots of trust is extremely important and situations like this should not scare us into depriving ourselves out of that. I say this as someone who runs an adblocking/fi…
I agree, modifying certificates shouldn't be technically impossible but perhaps we could have regulations where companies that do this are penalized. If companies are expected to safeguard customer then facilitating MITM is a huge breach that should result in fines.
A lot of root CAs are backed by national governments anyway, shouldn't they object to being impersonated?
It's also extremely common for companies to install root certificates on work computers that employees use to check their personal email. Why is nobody objecting to this?
Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks
#94Earlier quoted context omitted.
The really silly thing is that it's 2018 and the browser vendors still refuse to implement name based constraints on certificate authorities. It should be perfectly reasonable for a local, single domain CA to be generated and installed with the application. Instead we treat every CA as worthy to handle every domain always.
I'm not sure that's a browser thing. The X.509 spec specifies a field for that, which in OpenSSL would be called "subjectNameConstraints". The rules for the constraint can be found in RFC5280.[0] Mozilla have had an open development track for CA name constraints for quite some time, but the last edit to the page is from 2015.[1] I tried to actually use this field couple of years ago, and none of the existing tools I…
We could combined with some DNS records that states the policy for validating the certificate (stating the number of CAs to validate a given certificate).
It could be a huge improvement on security, and eliminating CAs as single point failures for the whole internet, at least for critical pieces of it.
Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks
#95Why are they deploying their own certificate into the root store???? This is shocking behaviour. What's the difference between this and malicious software.
Now imagine Companies where software development is not a priority and/or is not in the set of core competencies. As long as it functionally (kind of) works, it will be good enough.
Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks
#96Have any hardware companies ever written good accompanying software? From all the custom-ui graphics card config nonsense to utilities that phone home of their own accord, to things like this which are laughably awful. I feel glad I left for the mild shores of Linux in the early 00s.
Yeah, because on Linux the community has to support the hardware because the manufacturer doesn't even bother. Sounds way better...
Because it is.
Name one, just one, hardware manufacturer you can reach by email to report a bug and expect both your mail to be replied and the bug to be fixed. And without being charged a dime in the process (well deserved yet voluntary donations aside). No thanks, I'll stay with the Linux community any day.
Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks
#97Earlier quoted context omitted.
Yeah, because on Linux the community has to support the hardware because the manufacturer doesn't even bother. Sounds way better...
"Sounds way better..." Because it is. Name one, just one, hardware manufacturer you can reach by email to report a bug and expect both your mail to be replied and the bug to be fixed. And without being charged a dime in the process (well deserved yet voluntary donations aside). No thanks, I'll stay with the Linux community any day.
Further, you've clearly never had a critical outage happen during off hours. Try running to the community when your job is on the line at 3AM Christmas Day, let me know how responsive they are to you then.
You get the quality you pay for, and while the open source community is wonderful and amazing, it's done by people working for free, and subject to the whims of those people, which makes it A) unreliable B) inconsistent, and C) lower quality, on average.
Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks
#98Earlier quoted context omitted.
I have to STRONGLY disagree. It's a slippery slope towards a world in which the computers we use are completely locked down and we have no control over what they trust, being dictated by the corporations and their interests. The freedom to modify your roots of trust is extremely important and situations like this should not scare us into depriving ourselves out of that. I say this as someone who runs an adblocking/fi…
> The freedom to modify your roots of trust is extremely important. I agree, modifying certificates shouldn't be technically impossible but perhaps we could have regulations where companies that do this are penalized. If companies are expected to safeguard customer then facilitating MITM is a huge breach that should result in fines. A lot of root CAs are backed by national governments anyway, shouldn't they object to…
A question: if I'm on a work PC that has a root certificate installed, can you tell if they're using it to MITM? When I go to a site on my work PC with the padlock (eg my bank) and click to get more info, it does show the bank's certificate. Can they still be MITMing that connection?
Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks
#99Earlier quoted context omitted.
"Sounds way better..." Because it is. Name one, just one, hardware manufacturer you can reach by email to report a bug and expect both your mail to be replied and the bug to be fixed. And without being charged a dime in the process (well deserved yet voluntary donations aside). No thanks, I'll stay with the Linux community any day.
It's not, not even remotely. You clearly haven't actually lived day-to-day with Linux or you'd know how buggy and unreliable the random drivers for less-than-popular hardware actually is. Further, you've clearly never had a critical outage happen during off hours. Try running to the community when your job is on the line at 3AM Christmas Day, let me know how responsive they are to you then. You get the quality you pa…
That's a bit extreme. Of course throwing a shitload of money at support contracts will give you helpdesks answering during holidays and drones flocking into the data center, but that applies only to a very small subset of hw/sw products where any outage can be fatal. The consumer market is just a bit different though.
Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks
#100Earlier quoted context omitted.
> The freedom to modify your roots of trust is extremely important. I agree, modifying certificates shouldn't be technically impossible but perhaps we could have regulations where companies that do this are penalized. If companies are expected to safeguard customer then facilitating MITM is a huge breach that should result in fines. A lot of root CAs are backed by national governments anyway, shouldn't they object to…
> It's also extremely common for companies to install root certificates on work computers that employees use to check their personal email. Why is nobody objecting to this? A question: if I'm on a work PC that has a root certificate installed, can you tell if they're using it to MITM? When I go to a site on my work PC with the padlock (eg my bank) and click to get more info, it does show the bank's certificate. Can t…
Also,
It's also extremely common for companies to install root certificates on work computers that employees use to check their personal email. Why is nobody objecting to this?
Because you do not own those computers, and they should not be used for non-work-related activity. The company policy will explicitly mention this, something like "all communications on company property are subjected to monitoring at all times."