Earlier quoted context omitted.
First thing I did when I saw that URL was to run it through Qualys' SSL Labs test. Multiple issues, no forward secrecy, weak ciphers, grade set to 'C'. Oh, the irony. https://www.ssllabs.com/ssltest/analyze.html?d=howsmyssl.com
Uh, because it needs to allow weak clients to connect in order to report on them?
Lenovo Caught Installing Adware on New Computers
401–410 of 435 posts
Re: Lenovo Caught Installing Adware on New Computers
#402Earlier quoted context omitted.
He didn't find the password in the clear, he found the private key in the clear. He brute-forced the password. I assume his reasoning for looking for the private key was similar to: this program creates a new certificate authority and installs it on this computer. In order to do this, it must have all necessary tools for doing so, including the private key it uses to create those certificates, in memory somewhere. Ev…
Read it again, he found the password in cleartext in the memory dump. From the blogpost: > I tried the small dictionary john.dict that comes with John-the-Ripper, and it didn't find anything. But of course, I don't need a real dictionary. The password is probably also in the clear in the memory dump. I could just use the file super.txt as my dictionary! I tried this, but it was taking a long time, with 150k unique li…
Re: Lenovo Caught Installing Adware on New Computers
#403Earlier quoted context omitted.
Asus is about it.
I thought so too, but my recent experience with a Zenbook has changed my view. WiFi drivers were so bad it took half a year after my purchase before the connection became stable (not dropping every 15 minutes requiring a reboot). Touchpad drivers were also a mess with awful kinetic scrolling. And just couple of weeks ago it stopped booting Windows altogehter (something related to ACPI I guess, Linux works if I don't…
Additionally, a roommate spilled a pint of beer on my computer and Asus replaced it for free, despite not having an accidental damage warranty.
Re: Lenovo Caught Installing Adware on New Computers
#404Earlier quoted context omitted.
Not if the proxy checks the certificate of the site it's connecting to and doesn't trust it's own self-signed cert (there is no point in doing so if it's pure adware). But yeah... I have no idea what it does...
I honestly doubt that someone who was clueless and lazy enough to use the same self-signed certificate on all machines would put in the extra effort not to trust that certificate. Besides, the certificate is left behind after the software's uninstalled and no longer proxying connections.
http://www.komodia.com/wiki/index.php?title=SSL_Digestor#Cer...
"Also the module tries to verify that the certificate is indeed signed by an approved signer, it will use the CA store of the browser used to verify that (for Internet Explorer the Windows store will be used, and for Firefox the NSS store will be used), if the certificate isn't legit, the created certificate will be created in a way it would raise an alert to protect the user."
A huge ugly hack...
Re: Lenovo Caught Installing Adware on New Computers
#405Earlier quoted context omitted.
That appears to be the act of a nation-state though. I don't really sweat those, because I'm pretty sure if the NSA really wants in to my machine, I can't stop them.
They don't want in to just your machine though, they want a backdoor in to everyones machine, by default, without cause.
I have a lot of friends who haven't figured out the whole security-as-a-spectrum thing, and they spend a lot of time giving themselves grey hairs over adversaries that 1) they can't beat, 2) aren't worth beating, and 3) don't care about them anyway.
Re: Lenovo Caught Installing Adware on New Computers
#406Earlier quoted context omitted.
The premium isn't as high as you think, particularly if you account for resale value. Didn't Priceonomics do a feature on this?
I'm not sure why anyone buys anything other than a home when accounting for resale value unless they're just trying to pull a pump-and-dump. For laptops, at least, I buy them and use them until they die. I've only owned three laptops in my life.
Re: Lenovo Caught Installing Adware on New Computers
#407Re: Lenovo Caught Installing Adware on New Computers
#408This is much worse than just installing adware. They install a web proxy which MITMs all web connections, including HTTPS by means of a pre-installed trusted root certificate. The root certificate is the same across all installs, and the private key is present on the machine (necessarily, to operate the proxy): https://twitter.com/fugueish/status/568258997578371072 Someone will extract the private key in the next few…
Re: Lenovo Caught Installing Adware on New Computers
#409Earlier quoted context omitted.
Watch out, batter life is pretty crap! (About 2 hrs on my < 2yr old one)
The ones just released have a 15 hour battery (which even if it halves, is pretty good)