Live data from Hacker News

Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

bug1134506.bugzilla.mozilla.org

131–140 of 188 posts

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#131

Earlier quoted context omitted.

Windows 7 is going to be absolutely fine. If it's what she's used to, and you have the license and media, just go ahead. And something like TeamViewer does the remote support nicely. I'm all for Linux otherwise, but in this use case I'd let old people use whatever keeps them going.

Yeah, it's just an insecure mess. She always makes a mess of Windows machines. If her first instinct weren't always to call my older brother for help, I'd have gotten her the Mac ages ago.

Well, perhaps it would be good to give her a non-admin account to Windows? The same approach you'd do with a Mac, but leaving her with a familiar UI.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#132
post #90

While this whole Superfish/Lenovo thing is certainly quite scary, let's not forget the very important fact that, currently, the user ultimately still has the ability to modify the software on the machines he/she owns, which includes among other things (un)installing software like Superfish, and also adding/removing trusted certificates. There will be those who advocate locking down the certificate stores and other ar…

I'm very hesitant to use this word, but this is a very privileged position. Many customers don't have the skills to even see the technical problem while expecting that not to happen. The same goes for reinstalling the machine (or they don't trust in their skills).

Perhaps not, but such customers CAN purchase software written by someone who DOES have the skills, that will perform the actions on their behalf.

If the machine is locked down to prevent that, then the customers have no such option.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#134
post #109
post #58

Earlier quoted context omitted.

If your boss owns the tools with which you do your work, they have the right to dictate how you use them. Use personal devices for personal computing.

Not in Germany, not if there is even a minimum amount of using the computer for private purposes permitted.

That's interesting. So if it is forbidden to use the computer for anything personal, employers are allowed to snoop?

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#136

Earlier quoted context omitted.

Yeah, it's just an insecure mess. She always makes a mess of Windows machines. If her first instinct weren't always to call my older brother for help, I'd have gotten her the Mac ages ago.

Well, perhaps it would be good to give her a non-admin account to Windows? The same approach you'd do with a Mac, but leaving her with a familiar UI.

Privilege escalation, even with UAC at its strictest, is trivial on Windows with the malware that's floating around these days.

I worked full time for 5 of the last 6 years on Windows malware research. Windows is a swiss-cheese joke of an operating system that won't progress because of a(n at this point pathological) need for 20 years of backwards compatibility. Microsoft: make use of that XP mode VM and extend that trend forwards, you fools.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#137

While this whole Superfish/Lenovo thing is certainly quite scary, let's not forget the very important fact that, currently, the user ultimately still has the ability to modify the software on the machines he/she owns, which includes among other things (un)installing software like Superfish, and also adding/removing trusted certificates. There will be those who advocate locking down the certificate stores and other ar…

> let's not forget the very important fact that, currently, the user ultimately still has the ability to modify the software on the machines he/she owns

What about hard-disk firmware being re-flashed by the "Equation Group" [0]? No easy possibility to detect if you are infected, nor what it is actually doing, not even to reinstall. Hard-disk firmware is software too.

[0]: https://news.ycombinator.com/item?id=9058701

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#139
post #79

Earlier quoted context omitted.

They definitely can blacklist the certificate. They have the choice of having HTTPS effectively useless (by leaving the certificate there), or making HTTPS not work (by removing it, thus prompting action from the user to fix it -- perhaps by calling their tech savvy nephew). Browser vendors should (and usually do) err on the side of security.

Or the users just switch to a browser that works. IE or Chrome :(

[deleted]

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#140

While this whole Superfish/Lenovo thing is certainly quite scary, let's not forget the very important fact that, currently, the user ultimately still has the ability to modify the software on the machines he/she owns, which includes among other things (un)installing software like Superfish, and also adding/removing trusted certificates. There will be those who advocate locking down the certificate stores and other ar…

> While this whole Superfish/Lenovo thing is certainly quite scary, let's not forget the very important fact that, currently, the user ultimately still has the ability to modify the software on the machines he/she owns, which includes among other things (un)installing software like Superfish, and also adding/removing trusted certificates.

Go into a room full of average computer users. Say what you just said here, and watch the blank stares and listen to the "what did he just say/what language is he speaking" comments.

You seem to forget this is on consumer laptops, not machines that will be bought by enterprise IT departments and wiped/reinstalled for company use. The affected laptops are ending up in Joe and Jane User's homes, where they will immediately begin visiting their banks, social networks, email providers, and any other sites people use daily, and will therefore be vulnerable out of the box. They won't know about a root certificate; they won't even know what a root certificate is!

THAT is why this is such a shitty thing for Lenovo and Superfish to do.

Post reply on HN