Live data from Hacker News

Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

bug1134506.bugzilla.mozilla.org

91–100 of 188 posts

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#91
post #29

Earlier quoted context omitted.

TIL Google is ok if you get backdoored by your boss.

The company I work for has a strict policy of no direct outbound connections from the corporate network. This is to prevent (or just make harder) for compromised machines from "phoning home". This has the unfortunate side effect that all internet traffic must go through a proxy, they have to MiTM SSL traffic. I just use my smartphone's data for any personal internet browsing.

Are compromised machines on your corporate network a common problem? It seems like the problem is the compromised machines, not the phoning home. :)

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#92

Earlier quoted context omitted.

Komodia's own info says that it will generate an invalid certificate if the real certificate was invalid or untrusted "so it will not cause a security problem". They may be lying, but that page is fairly open about the way it works: http://www.komodia.com/wiki/index.php?title=SSL_Digestor#Cer...

I wouldn't go as far as say lying, they just failed to consider the SAN. Unfortunately they pulled the doc, possibly due to what they claim to be a DDOS but it's still in Google cache: http://webcache.googleusercontent.com/search?q=cache:XUbVSX8...

'SAN'?

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#93
post #84

I originally discovered this issue a month ago when debugging my friend's Lenovo laptop. Neither chrome nor IE can render battle.net correctly because the HTML injection is not properly escaped. Since the problem persists after a fresh recovery, I guess it's from some pre-installed software. I almost reported it to FBI.

Should this fall under the original brief of the NSA? (Ironic, I know). I realize that FBI traditionally does "domestic" and CIA "foreign" -- but I seem to recall NSA has something about "cybersecurity threats" or some such nebulus thing in their mission statement?

Yeah, but it would mean that NSA was actually doing its fucking job instead of being dickless douchebags.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#95
post #42
post #11

Shouldn't Lenovo be issuing a recall and pulling all the inventory in their distribution channel? In other words, Best Buy shouldn't be selling these things!

I believe Lenovo's official statement previously said "We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns." However, it now has a link to LEN-2015-010, a high-severity security vulnerability. http://news.lenovo.com/article_display.cfm?article_id=1929 https://news.ycombinator.com/item?id=9074676 http://support.lenovo.com/us/en/product_security/superfish

They didn't even close all their parentheses.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#96
post #85

Earlier quoted context omitted.

This. I can tell several stories of trying to set things up for my parents, only to have to call them/wait until I fly home next to fix something. Lessons have been learned the hard way on dumb email chains/anti-virus software, but trying to give them a list of browser settings (among other things) to do is getting to be too much. So, now what?

Use some software with which you can do remote maintenance on your parents' computer(s). Or, introduce them to more stable OSses, like Ubuntu instead of Windows. That worked for my neighbours ;-)

I've thought about Ubuntu...but it's a comfort thing. I'm afraid that telling my parents "hey so this new thing is more stable...." and it'll just trail off after that. For now, I'm afraid, I'll just keep fighting the good fight.

Remote maintenance is probably something I should look more into.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#97
post #66
post #4

This is a PDF attached to this issue, requesting blacklisting of the Superfish certificate: https://bugzilla.mozilla.org/show_bug.cgi?id=1134506

From what I understand of Superfish, Mozilla (and other browser vendors) can't just blacklist the certificate. That would make all HTTPS connections error out. A message notifying users of the issue is all they can do.

That's not their problem. It's Lenovo who'll be getting the support calls for their defective, sorry, "enhanced" product

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#98
post #92

Earlier quoted context omitted.

I wouldn't go as far as say lying, they just failed to consider the SAN. Unfortunately they pulled the doc, possibly due to what they claim to be a DDOS but it's still in Google cache: http://webcache.googleusercontent.com/search?q=cache:XUbVSX8...

'SAN'?

http://en.wikipedia.org/wiki/SubjectAltName

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#99
post #92

Earlier quoted context omitted.

I wouldn't go as far as say lying, they just failed to consider the SAN. Unfortunately they pulled the doc, possibly due to what they claim to be a DDOS but it's still in Google cache: http://webcache.googleusercontent.com/search?q=cache:XUbVSX8...

'SAN'?

SubjectAltName.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#100

Any idea why it doesn't affect Firefox?

Firefox has it's own certificate store. Both IE and Chrome utilize the Windows store.

But as pointed out in other comments, it looks like SuperFish does install the extra cert in Firefox's database too, but only after a restart.
Post reply on HN