Live data from Hacker News

Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

bug1134506.bugzilla.mozilla.org

101–110 of 188 posts

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#101
post #17

Earlier quoted context omitted.

Chrome does do pinning, but ignores pins when the cert parent is a privately installed cert (because this is a "feature" used by many enterprises). """ Chrome does not perform pin validation when the certificate chain chains up to a private trust anchor. A key result of this policy is that private trust anchors can be used to proxy (or MITM) connections, even to pinned sites. 'Data loss prevention' appliances, firewa…

And the rationale: "We deem this acceptable because the proxy or MITM can only be effective if the client machine has already been configured to trust the proxy’s issuing certificate" I think that's fair, or at least it has traditionally been a fair assumption for most users. The issue here is that your hardware vendor has compromised your machine, so that is no longer a fair assumption.

There's another issue with ignoring cert pining with user-added root certificates: if you add a root certificate that's missing on your client machine (for instance CAcert or your national CA like ICP-Brasil), the CA you added can bypass pining, even though it shouldn't be able to.

On Mozilla, you can configure it to never bypass pining (security.cert_pinning.enforcement_level set to 2, see https://wiki.mozilla.org/SecurityEngineering/Public_Key_Pinn... ); I don't know how to do it on Chrome.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#102
post #29

Earlier quoted context omitted.

TIL Google is ok if you get backdoored by your boss.

The company I work for has a strict policy of no direct outbound connections from the corporate network. This is to prevent (or just make harder) for compromised machines from "phoning home". This has the unfortunate side effect that all internet traffic must go through a proxy, they have to MiTM SSL traffic. I just use my smartphone's data for any personal internet browsing.

What does your company do if you have to access a TLS site which uses client certificates for authentication? AFAIK, client certificates don't work when there's a MITM on the TLS traffic, since the MITM proxy doesn't have a way to produce a client certificate that will be accepted by the server.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#103
post #84

I originally discovered this issue a month ago when debugging my friend's Lenovo laptop. Neither chrome nor IE can render battle.net correctly because the HTML injection is not properly escaped. Since the problem persists after a fresh recovery, I guess it's from some pre-installed software. I almost reported it to FBI.

Should this fall under the original brief of the NSA? (Ironic, I know). I realize that FBI traditionally does "domestic" and CIA "foreign" -- but I seem to recall NSA has something about "cybersecurity threats" or some such nebulus thing in their mission statement?

No. The FBI handles cybercrime. The NSA is under the DoD.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#104
post #84

Earlier quoted context omitted.

Should this fall under the original brief of the NSA? (Ironic, I know). I realize that FBI traditionally does "domestic" and CIA "foreign" -- but I seem to recall NSA has something about "cybersecurity threats" or some such nebulus thing in their mission statement?

No. The FBI handles cybercrime. The NSA is under the DoD.

But this isn't (just) cybercrime. This could be seen as weakening the ("cyber"-)infrastructure. But maybe that's just under "Homeland Security" now (of which FBI is a part?)?

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#105
post #28

I originally discovered this issue a month ago when debugging my friend's Lenovo laptop. Neither chrome nor IE can render battle.net correctly because the HTML injection is not properly escaped. Since the problem persists after a fresh recovery, I guess it's from some pre-installed software. I almost reported it to FBI.

Shouldn't Lenovo be guilty of hacking and illegal wiretaps?

To be guilty of wire fraud, Lenovo must have intent to defraud the user out of money. It will be tricky to prosecutte.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#106
post #79
post #66

Earlier quoted context omitted.

From what I understand of Superfish, Mozilla (and other browser vendors) can't just blacklist the certificate. That would make all HTTPS connections error out. A message notifying users of the issue is all they can do.

They definitely can blacklist the certificate. They have the choice of having HTTPS effectively useless (by leaving the certificate there), or making HTTPS not work (by removing it, thus prompting action from the user to fix it -- perhaps by calling their tech savvy nephew). Browser vendors should (and usually do) err on the side of security.

Or the users just switch to a browser that works. IE or Chrome :(

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#107
post #11

Shouldn't Lenovo be issuing a recall and pulling all the inventory in their distribution channel? In other words, Best Buy shouldn't be selling these things!

Pulling unsold inventory would be in some ways far harder to do for the consumer computing industry than many other industries more commonly known for recalls (auto, pharma, etc) - these laptops won't just be sold at the large outlets that have properly managed supplier relationships with Lenovo, they'll also be sold at innumerable tiny independent stores, that probably got their stock from a reseller - or even a reseller of a reseller. Thus tracking down all the stock and issuing recall notices would be hard.

But recalling already-sold inventory? Even disregarding the difficulty and inconvenience, this would be a terrible idea. In order for them to be able to remove this, they'd need to be able to log in to your computer, and change the security settings, as well as modify the recovery partition. I doubt I need to explain why giving your login credentials to Lenovo is a terrible idea!

In reality then they've done the only reasonable thing they could do - post a statement with clear removal instructions. They didn't have a lot of choice admittedly, so I'm not particularly lauding them for this - once you've made enough of a mistake to appear in mainstream media (the story was on the BBC website, and there was a fairly large article in my newspaper this morning), you can't really get away with doing nothing if you'd like to continue selling laptops.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#108
post #11

Shouldn't Lenovo be issuing a recall and pulling all the inventory in their distribution channel? In other words, Best Buy shouldn't be selling these things!

According to the Wall Street Journal [1], Lenovo are going to release a program that completely removes Superfish from their PCs. > WSJ: What are you doing now to ensure the security of people who bought Lenovo laptops with the Superfish app? > Hortensius: As soon as the programmer is finished, we will provide a tool that removes all traces of the app from people’s laptops; this goes further than simply uninstalling…

Also from this Article:

❝WSJ: Isn’t the best prevention tool to simply stop pre-loading any software on Lenovo computers?

Hortensius: In general, we get pretty good feedback from users on what software we pre-install on computers.❞

Probably it would be a good idea, if this is really what the company things is true, that upon first boot a menu is opened asking for the particular programs to install?

    Thanks for buying a Lenovo product. To get the most out of
    your new high-performance mobile workstation, the following
    software products can be installed free of charge by ticking the
    check-box and clicking 'Next'.

    [x] Superfish Ad-Injector, making your web-browsing experience
        miserable and yourself vulnerable to Man-in-the-Middle-Attacks
        when doing facebook and online banking.

    [x] Limited trial of Super-High-Security-Internet-
        Security-Anti-Vius which will constantly nag you about paying
        for the full product

    (...)

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#109
post #58
post #29

Earlier quoted context omitted.

TIL Google is ok if you get backdoored by your boss.

If your boss owns the tools with which you do your work, they have the right to dictate how you use them. Use personal devices for personal computing.

Not in Germany, not if there is even a minimum amount of using the computer for private purposes permitted.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#110
post #50

Earlier quoted context omitted.

Well you don't have to MITM SSL in order to proxy it, it can be done in other ways. They probably choose to do so in order to see the details of the request.

Correct, the firewall intercepts all traffic looking for potential compromises and blocks it. Given all these corporations getting hacked, such measures seem necessary.

Conclusion does not follow from premise. Once an attacker's code is running on machines that have access to sensitive data, you've already lost - there's no way to prevent it smuggling the data out in legitimate-looking requests. The right way is to stop the bad stuff getting in in the first place.
Post reply on HN