Live data from Hacker News

Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

bug1134506.bugzilla.mozilla.org

31–40 of 188 posts

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#31

I went to Best Buy as well today and picked up a laptop to look into this further. The Superfish software is not properly passing the validation state of the public cert when it connects to a website like Bank of America as an example. There's no need to export their private and use it in a MitM transparent proxy. The software is simply not triggering appropriate warnings when provided an obviously fake certificate t…

I suppose they were relying on the prepending of "verify_fail" to the hostname (with an invalid character - '_') to cause the browser to fail the certificate name check, so Superfish is doing certificate checking? Shouldn't the browser then complain with a "certificate's hostname does not match the site's" warning?

...Or am I looking at this in the wrong way?

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#32

I went to Best Buy as well today and picked up a laptop to look into this further. The Superfish software is not properly passing the validation state of the public cert when it connects to a website like Bank of America as an example. There's no need to export their private and use it in a MitM transparent proxy. The software is simply not triggering appropriate warnings when provided an obviously fake certificate t…

I suppose they were relying on the prepending of "verify_fail" to the hostname (with an invalid character - '_') to cause the browser to fail the certificate name check, so Superfish is doing certificate checking? Shouldn't the browser then complain with a "certificate's hostname does not match the site's" warning? ...Or am I looking at this in the wrong way?

You're close. I'm not in the business of telling people how to exploit this and am assuming those who already know were already doing it based on what would be a "best practice" (for a bad guy that is) when it comes to generating a self-signed cert.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#33
This isn't right though.

I got a Lenovo Y50 a couple weeks ago, and when I downloaded Firefox and looked at the certificate, it was Superfish.

I've since uninstalled Superfish and deleted the keys (I exported them first though). I know I probably should reinstall Windows but I'm too lazy.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#34

I went to Best Buy as well today and picked up a laptop to look into this further. The Superfish software is not properly passing the validation state of the public cert when it connects to a website like Bank of America as an example. There's no need to export their private and use it in a MitM transparent proxy. The software is simply not triggering appropriate warnings when provided an obviously fake certificate t…

Does anyone have a security contact at Superfish? It looks like they don't have a security@ mailbox: "DB3FFO11OLC004.mail.protection.outlook.com rejected your message to the following email addresses: security@superfish.com Something went wrong and your message couldn't be delivered. This could be a temporary issue. Try resending the message in a few minutes. If that doesn't work, forward this message to your email a…

Try abuse or postmaster or one of these:

http://whois.domaintools.com/superfish.com

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#35
Not only did I have to remove the certificate from my root authority in the control panel, I also had to remove it from my list of certificates in Firefox. This was after uninstalling Superfish. Once I did all of these things, and cleared my history and cache and all that, the website that folks have been linking said that it didn't detect Superfish (sorry, I'm typing this from a phone).

So my explanation wasn't very technical, but I feel as though the part of the process where you also remove the certificate from Firefox had been left out, and I wanted to share it in case it helps out another person.

This news took me by surprise, as I just received a brand new Lenovo Yoga 2 for work last week, and it had this vulnerability.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#36

Not only did I have to remove the certificate from my root authority in the control panel, I also had to remove it from my list of certificates in Firefox. This was after uninstalling Superfish. Once I did all of these things, and cleared my history and cache and all that, the website that folks have been linking said that it didn't detect Superfish (sorry, I'm typing this from a phone). So my explanation wasn't very…

You're right. Further discussion in that bug and on twitter [1] confirm that Firefox is affected after a restart. The author of this didn't restart.

So any removal instructions which don't include clearing out Firefox's certificates are incomplete. This includes Lenovo's published instructions.

[1] - https://twitter.com/FiloSottile/status/568600661534875648

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#37
post #29
post #17

Earlier quoted context omitted.

Chrome does do pinning, but ignores pins when the cert parent is a privately installed cert (because this is a "feature" used by many enterprises). """ Chrome does not perform pin validation when the certificate chain chains up to a private trust anchor. A key result of this policy is that private trust anchors can be used to proxy (or MITM) connections, even to pinned sites. 'Data loss prevention' appliances, firewa…

TIL Google is ok if you get backdoored by your boss.

The company I work for has a strict policy of no direct outbound connections from the corporate network. This is to prevent (or just make harder) for compromised machines from "phoning home".

This has the unfortunate side effect that all internet traffic must go through a proxy, they have to MiTM SSL traffic.

I just use my smartphone's data for any personal internet browsing.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#38
post #29
post #17

Earlier quoted context omitted.

Chrome does do pinning, but ignores pins when the cert parent is a privately installed cert (because this is a "feature" used by many enterprises). """ Chrome does not perform pin validation when the certificate chain chains up to a private trust anchor. A key result of this policy is that private trust anchors can be used to proxy (or MITM) connections, even to pinned sites. 'Data loss prevention' appliances, firewa…

TIL Google is ok if you get backdoored by your boss.

Common practice in some workplaces.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#39
post #7

Earlier quoted context omitted.

And this matters because even if you uninstall the program, it leaves the certificate behind, right? So you have to manually remove the cert to shield yourself against future attacks, in addition to removing the program

Not that this excuses Lenovo in any regard whatsoever, the removal instructions[1] Lenovo link to in their press release[2][3] includes the removal of a certificate. [1] http://support.lenovo.com/us/en/product_security/superfish_u... [2] http://news.lenovo.com/article_display.cfm?article_id=1929 [3] http://support.lenovo.com/us/en/product_security/superfish

Good, though TBH, it didn't include removal of a certificate just few hours ago. I guess they're breaking under the pressure of PR shitstorm.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#40
While this whole Superfish/Lenovo thing is certainly quite scary, let's not forget the very important fact that, currently, the user ultimately still has the ability to modify the software on the machines he/she owns, which includes among other things (un)installing software like Superfish, and also adding/removing trusted certificates. There will be those who advocate locking down the certificate stores and other areas of the OS (e.g. only "approved" software can be installed) in an effort to prevent companies from doing things like this, but I think that could lead to an even worse situation - imagine if this was preinstalled on a locked-down system that made it nearly impossible to remove (or perhaps even discover!)

To put it bluntly, I'd still prefer to buy a system "infected" with Superfish but which lets me reinstall the OS and configure it however I choose, than one which is locked-down so much that, even if such malware was not present initially, if something similarly undesirable is eventually installed by default, it would be nearly impossible to remove. Of course buying an open system that has no malware/adware preinstalled is even better, but given the way things seem to be going with "smart TVs" adding ads and whatnot, it feels like that might not be an option in the future.

Post reply on HN