Earlier quoted context omitted.
Maybe it triggers the logic that allows (supposedly) user-added certs to override those pins? (Google was pressured into adding such logic by corporate users, whose IT departments want to -- supposedly openly -- MITM employees' connections.) Edit: I think that's the case. AGL's original announcement of pinning said: "There are a number of cases where HTTPS connections are intercepted by using local, ephemeral certifi…
> Google was pressured into adding such logic by corporate users, whose IT departments want to -- supposedly openly -- MITM employees' connections "openly"? Why doesn't the user see that a fake certificate is being used then? There is no excuse for not showing a big fat warning. This only shows which side Google is really on when it's evil corporations vs. you, the user.
Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
61–70 of 188 posts
Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#62Earlier quoted context omitted.
Does anyone have a security contact at Superfish? It looks like they don't have a security@ mailbox: "DB3FFO11OLC004.mail.protection.outlook.com rejected your message to the following email addresses: security@superfish.com Something went wrong and your message couldn't be delivered. This could be a temporary issue. Try resending the message in a few minutes. If that doesn't work, forward this message to your email a…
Try abuse or postmaster or one of these: http://whois.domaintools.com/superfish.com
Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#63Earlier quoted context omitted.
I'm somewhat puzzled by the single certificate. Couldn't they have generated a new signing request and self-signed on each machine - at least ensuring that each customer has a unique cert for their proxy?
These guys aren't the brightest bulbs out there. You could even have it switch certificates on every reboot... or not do this in the first place. ;-)
Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#64Computing is genuinely becoming scary. If I didn't browse tech sites or spend my days on HackerNews, I probably wouldn't know about these things. I'm getting older and more disinterested in the constant maintenance -- I just want the shit to work. It sucks the most for those who learned "don't install anything fishy, run a virus scan, don't open attachments, and you'll be fine." They bought a computer and followed th…
(PDFs can be malware, too.)
Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#65While this whole Superfish/Lenovo thing is certainly quite scary, let's not forget the very important fact that, currently, the user ultimately still has the ability to modify the software on the machines he/she owns, which includes among other things (un)installing software like Superfish, and also adding/removing trusted certificates. There will be those who advocate locking down the certificate stores and other ar…
Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#66This is a PDF attached to this issue, requesting blacklisting of the Superfish certificate: https://bugzilla.mozilla.org/show_bug.cgi?id=1134506
Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#67This is a PDF attached to this issue, requesting blacklisting of the Superfish certificate: https://bugzilla.mozilla.org/show_bug.cgi?id=1134506
From what I understand of Superfish, Mozilla (and other browser vendors) can't just blacklist the certificate. That would make all HTTPS connections error out. A message notifying users of the issue is all they can do.
Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#68Earlier quoted context omitted.
It is true. I can't remember where I read it, but I remember seeing it either here on HN or on Twitter.
Komodia's own info says that it will generate an invalid certificate if the real certificate was invalid or untrusted "so it will not cause a security problem". They may be lying, but that page is fairly open about the way it works: http://www.komodia.com/wiki/index.php?title=SSL_Digestor#Cer...
http://webcache.googleusercontent.com/search?q=cache:XUbVSX8...
Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#69Earlier quoted context omitted.
TIL Google is ok if you get backdoored by your boss.
If your boss owns the tools with which you do your work, they have the right to dictate how you use them. Use personal devices for personal computing.
The line between what computing should be done on what device is blurry in both directions -- it's not just "people do personal computing on corporate devices". It'd be a bit strange to hear a boss tell me to never browse Amazon or Hacker News during lunch.
Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#70Computing is genuinely becoming scary. If I didn't browse tech sites or spend my days on HackerNews, I probably wouldn't know about these things. I'm getting older and more disinterested in the constant maintenance -- I just want the shit to work. It sucks the most for those who learned "don't install anything fishy, run a virus scan, don't open attachments, and you'll be fine." They bought a computer and followed th…
I can tell several stories of trying to set things up for my parents, only to have to call them/wait until I fly home next to fix something. Lessons have been learned the hard way on dumb email chains/anti-virus software, but trying to give them a list of browser settings (among other things) to do is getting to be too much.
So, now what?