Earlier quoted context omitted.
The company I work for has a strict policy of no direct outbound connections from the corporate network. This is to prevent (or just make harder) for compromised machines from "phoning home". This has the unfortunate side effect that all internet traffic must go through a proxy, they have to MiTM SSL traffic. I just use my smartphone's data for any personal internet browsing.
Are compromised machines on your corporate network a common problem? It seems like the problem is the compromised machines, not the phoning home. :)
Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
111–120 of 188 posts
Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#112Earlier quoted context omitted.
From what I understand of Superfish, Mozilla (and other browser vendors) can't just blacklist the certificate. That would make all HTTPS connections error out. A message notifying users of the issue is all they can do.
That's not their problem. It's Lenovo who'll be getting the support calls for their defective, sorry, "enhanced" product
Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#113Earlier quoted context omitted.
Way to completely disregard the rest of the parent's comment, which makes a fantastic point, and instead blindly call him an idiot.
You're right. Still, it would be better to just say nothing, so as not to dilute the thread further. The right tool here is flagging. You can flag an inappropriate comment by clicking on its timestamp to go to its page, then clicking on "flag". Fortunately, enough other users did so that the comment was killed.
Is comment flagging hidden from the main page to prevent accidental clicks, or its use as a "super downvote"?
Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#114Shouldn't Lenovo be issuing a recall and pulling all the inventory in their distribution channel? In other words, Best Buy shouldn't be selling these things!
Pulling unsold inventory would be in some ways far harder to do for the consumer computing industry than many other industries more commonly known for recalls (auto, pharma, etc) - these laptops won't just be sold at the large outlets that have properly managed supplier relationships with Lenovo, they'll also be sold at innumerable tiny independent stores, that probably got their stock from a reseller - or even a res…
They could offer to re-image the hard drive with a non-infected image.
Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#115Earlier quoted context omitted.
Use some software with which you can do remote maintenance on your parents' computer(s). Or, introduce them to more stable OSses, like Ubuntu instead of Windows. That worked for my neighbours ;-)
I've thought about Ubuntu...but it's a comfort thing. I'm afraid that telling my parents "hey so this new thing is more stable...." and it'll just trail off after that. For now, I'm afraid, I'll just keep fighting the good fight. Remote maintenance is probably something I should look more into.
Though I admit I am starting to worry about the program itself as it's now warning about "missing antivirus" and such, but it's not gone over the deep end just yet.
Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#116I originally discovered this issue a month ago when debugging my friend's Lenovo laptop. Neither chrome nor IE can render battle.net correctly because the HTML injection is not properly escaped. Since the problem persists after a fresh recovery, I guess it's from some pre-installed software. I almost reported it to FBI.
Shouldn't Lenovo be guilty of hacking and illegal wiretaps?
Everything else is not acceptable.
Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#117Earlier quoted context omitted.
I've thought about Ubuntu...but it's a comfort thing. I'm afraid that telling my parents "hey so this new thing is more stable...." and it'll just trail off after that. For now, I'm afraid, I'll just keep fighting the good fight. Remote maintenance is probably something I should look more into.
TeamViewer is a godsend for remote assistance. Free for personal use, paid for business. Though I admit I am starting to worry about the program itself as it's now warning about "missing antivirus" and such, but it's not gone over the deep end just yet.
For maintaining your mother-in-law's computer it's perfect.
Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#118Earlier quoted context omitted.
...is it blindly copying any x509v3 attributes present on the certificate, or just the one that you seem to be carefully not mentioning? Can you email me (one is listed in my HN profile)? I just thought of a pretty horrible exploit. 2199399413f2e63e6291a3f3e60f3475518aaf88215434222c65d6bc6fe41f34
I'm really just curious & not malicious - is that string at the end of your post a hash of a key or of an exploit code?
Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#119While this whole Superfish/Lenovo thing is certainly quite scary, let's not forget the very important fact that, currently, the user ultimately still has the ability to modify the software on the machines he/she owns, which includes among other things (un)installing software like Superfish, and also adding/removing trusted certificates. There will be those who advocate locking down the certificate stores and other ar…
Swift on Security has argued - quite convincingly IMHO - that as long as we have this attitude that the user "can" fix their machine by "just remove a SSL cert" we are going to utterly fail the vast majority of ordinary people who now depend on having a machine connected to the internet.
http://swiftonsecurity.tumblr.com/post/98675308034/a-story-a...
"Maybe this isn’t her fault. Maybe computer security for the average person isn’t a series of easy steps and absolutes they discard from our golden mouths of wise truths to spite the nerd underclass.
Perhaps it’s the very design of General Purpose Computing. And who built this world of freedom, a world that has so well served 17-year-old Jessica? You did. We did."
Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#120Earlier quoted context omitted.
That's not their problem. It's Lenovo who'll be getting the support calls for their defective, sorry, "enhanced" product
If the user installs a Firefox update and then all their HTTPS connections stop working, most users will blame Firefox unless the error messages are very specific about Lenovo's involvement, which simple blacklisting won't do. Users who follow technical news and understand the problem will already have removed the certificate manually (and removed the proxy).