Live data from Hacker News

Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks

bleepingcomputer.com

121–123 of 123 posts

Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks

#121
post #120

Earlier quoted context omitted.

Why would all your services have to be hosted in house and why would it prevent you from "exposing internal services" (I mean, apart from the fact that they kindof aren't internal services anymore from that point on)? For one, there is no problem hosting your own services elsewhere and having them use your own certificates. But more importantly: Why should your own CA prevent you from obtaining certificates from an e…

The big issue was identifying all the impacted services, reconfiguring all of them testing and redeploying them. If it’s a few services fine. But once it’s a few hundred it’s a pain.

Well ... but then that still has nothing to do with using your own root CA, does it? I mean, why would you want to suddenly reconfigure all of your services to use a different CA? It might come up here and there that you need external access to some service hat was internal before, but that is hardly a huge problem to reconfigure?!

And also, if you have so many services running that swapping out all of the certificates is a major headache, your primary mistake probably was that that wasn't automated? When keys are compromised, you should be able to reprovision anyway.

Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks

#122
post #82

Earlier quoted context omitted.

RMA for miserable sound ?

Bluetooth is absolute garbage for serious audio. Wired will always sound better, and a DAC + Amp driving the cans will always sound the best. Sennheiser does make BT headphones with a dedicated tower that helps a bit, but nothing can replace a hard line.

> Sennheiser does make BT headphones with a dedicated tower that helps a bit, but nothing can replace a hard line.

Their RS line of headphones don't actually use Bluetooth. Their older ones use the Kleer protocol, while the newer ones use a proprietary wireless protocol. Lossless audio in either case.

Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks

#123

Earlier quoted context omitted.

>Because you do not own those computers, and they should not be used for non-work-related activity. The company policy will explicitly mention this, something like "all communications on company property are subjected to monitoring at all times." Just as a thought experiment, lets say I set up a "free computer booth" on a street, but made people tick a box when they started that expressed the same conditions. Would I…

Yes. The owner always has the right to monitor what goes on with his/her property. If you remove that right (like what is happening on mobile devices, unfortunately), it's a slippery slope to a situation where no one has absolute ownership of what they "own", which is even more treacherous for privacy.

> Yes. The owner always has the right to monitor what goes on with his/her property.

No. By this logic your ISP owns the cables and has the right to MITM as well.

Post reply on HN