Earlier quoted context omitted.
They definitely can blacklist the certificate. They have the choice of having HTTPS effectively useless (by leaving the certificate there), or making HTTPS not work (by removing it, thus prompting action from the user to fix it -- perhaps by calling their tech savvy nephew). Browser vendors should (and usually do) err on the side of security.
Or the users just switch to a browser that works. IE or Chrome :(
Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
141–150 of 188 posts
Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#142Earlier quoted context omitted.
Well, perhaps it would be good to give her a non-admin account to Windows? The same approach you'd do with a Mac, but leaving her with a familiar UI.
Privilege escalation, even with UAC at its strictest, is trivial on Windows with the malware that's floating around these days. I worked full time for 5 of the last 6 years on Windows malware research. Windows is a swiss-cheese joke of an operating system that won't progress because of a(n at this point pathological) need for 20 years of backwards compatibility. Microsoft: make use of that XP mode VM and extend that…
Another option would be to put her regular use to a VM that you control (remotely) and can restore to a clean state at any time...
Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#143Computing is genuinely becoming scary. If I didn't browse tech sites or spend my days on HackerNews, I probably wouldn't know about these things. I'm getting older and more disinterested in the constant maintenance -- I just want the shit to work. It sucks the most for those who learned "don't install anything fishy, run a virus scan, don't open attachments, and you'll be fine." They bought a computer and followed th…
But the "regular" users won't. It's not that they _can't_. It's just that for them Internet-connected computers are just tools. Tools to get to information and services... or to get their jobs done. They don't want to mess around with systems - they just want to order something online or communicate with family and friends.
And they are buying laptops like these because they are inexpensive and seem to fit their needs. They just want a tool they can use.
They are _trusting_ Lenovo and other manufacturers. And that trust is being betrayed.
Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#144Earlier quoted context omitted.
I'm very hesitant to use this word, but this is a very privileged position. Many customers don't have the skills to even see the technical problem while expecting that not to happen. The same goes for reinstalling the machine (or they don't trust in their skills).
Perhaps not, but such customers CAN purchase software written by someone who DOES have the skills, that will perform the actions on their behalf. If the machine is locked down to prevent that, then the customers have no such option.
Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#145Earlier quoted context omitted.
Shouldn't Lenovo be guilty of hacking and illegal wiretaps?
To be guilty of wire fraud, Lenovo must have intent to defraud the user out of money. It will be tricky to prosecutte.
Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#146Earlier quoted context omitted.
From what I understand of Superfish, Mozilla (and other browser vendors) can't just blacklist the certificate. That would make all HTTPS connections error out. A message notifying users of the issue is all they can do.
One way would be to bypass the proxy if it's detected as a Superfish proxy by its certificate, but somehow I feel like this isn't a problem the browser vendors should be doing extra workarounds for (and giving precedence to "if we don't like your proxy we'll ignore it" isn't a great idea either.)
https://twitter.com/matthew_d_green/status/56843703790644428...
Probably not a proxy; probably low-level socket interception in Windows.
So there isn't much the browsers can do to help the user.
At least the technical side of Lenovo's response is all the way to "We are writing a program to remove the certificates", which is probably the thing that is going to impact the most people.
Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#147Earlier quoted context omitted.
Correct, the firewall intercepts all traffic looking for potential compromises and blocks it. Given all these corporations getting hacked, such measures seem necessary.
Conclusion does not follow from premise. Once an attacker's code is running on machines that have access to sensitive data, you've already lost - there's no way to prevent it smuggling the data out in legitimate-looking requests. The right way is to stop the bad stuff getting in in the first place.
Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#148While this whole Superfish/Lenovo thing is certainly quite scary, let's not forget the very important fact that, currently, the user ultimately still has the ability to modify the software on the machines he/she owns, which includes among other things (un)installing software like Superfish, and also adding/removing trusted certificates. There will be those who advocate locking down the certificate stores and other ar…
Many new systems now don't even come with original software disks requiring you to backup the machine using preinstalled crapware to create a backup DVD.
This was the case with a couple of laptops I purchased in the past three years; one of which was a Toshiba.
Years ago, when you purchased a machine, you got driver disk separately and even now I'm seeing a trend where that's becoming less the case.
At least this has been my experience.
Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#149Earlier quoted context omitted.
This. I can tell several stories of trying to set things up for my parents, only to have to call them/wait until I fly home next to fix something. Lessons have been learned the hard way on dumb email chains/anti-virus software, but trying to give them a list of browser settings (among other things) to do is getting to be too much. So, now what?
I'm in this situation too. We're at an impasse now too where my mom wants a new laptop. She doesn't want to learn anything new (Mac OS) and both she and I don't want to deal with Windows 8+. I'm skeptical about just installing Windows 7 on a newer laptop (...driver/hardware support). If I could get her to switch to Mac (she's in her 70s), I could set her up with a non-admin user account and set it up easily so that I…
Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#150Earlier quoted context omitted.
I'm very hesitant to use this word, but this is a very privileged position. Many customers don't have the skills to even see the technical problem while expecting that not to happen. The same goes for reinstalling the machine (or they don't trust in their skills).
Perhaps not, but such customers CAN purchase software written by someone who DOES have the skills, that will perform the actions on their behalf. If the machine is locked down to prevent that, then the customers have no such option.
Do you know that you have to?
How do you, with no software skills at all, evaluate whether the second person you bring it to does have the skills?