Live data from Hacker News

Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

bug1134506.bugzilla.mozilla.org

171–180 of 188 posts

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#171
post #125

Earlier quoted context omitted.

If you buy a computer from the Microsoft Store it is guaranteed to have no crapware, trialware or any other junk on it. If you buy a computer from somewhere else and take it to the Microsoft Store they will place a clean operating system on it for $99. For technical people of course, it is no big deal to install the OS yourself, but I have to say it was nice getting my last HP notebook without a single thing I had to…

There was a time I would have balked at the idea of paying Microsoft $99 to ensure there was no crape are on a PC. Now it sounds like a decent value.

To set up a new machine for a client I charge about $75 to:

Remove the pre-installed crap. (Using MCPR or NRT to remove bundled AV.)

Ensure MSE or Windows Defender is up and running.

Install the usual software - VLC, LibreOffice (or MS Office if they have bought it), Classic Start if Win 8 and wanted, Chrome with AdBlock (although may soon switch to uBlock), etc. Ninite does most of the heavy lifting on that.

Setup printer.

Set up local user accounts (after discussing Microsoft accounts.)

Transfer the user folder (and email if client-based, Thunderbird and Mozbackup usually does most of the work.)

Join the machine onto the broadband.

If necessary, go through the basics of Windows 8.1, web security, backups etc.

It's closer to $99 for businesses, but they usually have slightly more complex requirements.

---

We used to make restore disks, but nowadays we generally don't bother as it's faster to clean install from a Windows install that already has the updates on it.

I may very well start clean-installing the machines instead. One irritating thing I've come across is that "8.1 with Bing" wouldn't install from a standard Windows 8.1 disk. That may scupper the clean-install plan for home users with cheap machines.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#172

Earlier quoted context omitted.

After a little more thought, it seems obvious to me now what the problem is. :-) The shocking thing is that the certificate name matching algorithm has been standardised for over 15 years and yet those who wrote the cert generation code weren't aware of how browsers implement it.

Ding, ding, ding. ;-)

This is bumming me out. I'm really curious about what the exploit is but cannot quite put the pieces together...

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#173
post #23

Earlier quoted context omitted.

Ah, That explains it. Thanks! And to semenko too.

It points to an interesting problem that, while browser vendors officially think that users ought to be notified when someone is using an intercepting proxy -- that it shouldn't be invisible to them -- when users aren't installing their own OS or configuring their own browser, it could be completely invisible in practice. So the IT department-installed or OEM-installed cert is treated as "user-installed" by the pinni…

As someone who respects your work, I would suggest that perhaps the more interesting problem is EFF's structural inability to do anything but apologize for Google policies and practices that clearly and obviously harm user freedom and privacy.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#175
post #72

Earlier quoted context omitted.

You're right. Still, it would be better to just say nothing, so as not to dilute the thread further. The right tool here is flagging. You can flag an inappropriate comment by clicking on its timestamp to go to its page, then clicking on "flag". Fortunately, enough other users did so that the comment was killed.

I had no idea that was even an option, and I've been here for a few years now. I thought only threads could be flagged. Is comment flagging hidden from the main page to prevent accidental clicks, or its use as a "super downvote"?

It is an intentional speed-bump to cut down on reflexive flagging.

Since the feature is non-obvious, I post descriptions like the above semi-regularly in the hope of getting the word out.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#176

While this whole Superfish/Lenovo thing is certainly quite scary, let's not forget the very important fact that, currently, the user ultimately still has the ability to modify the software on the machines he/she owns, which includes among other things (un)installing software like Superfish, and also adding/removing trusted certificates. There will be those who advocate locking down the certificate stores and other ar…

Welcome to the War over General-Purpose Computing. http://boingboing.net/2012/08/23/civilwar.html http://boingboing.net/2012/01/10/lockdown.html The future really scares me. And yes, backlash from Superfish fiasco will probably only make things worse.

I don't understand how this would be the conclusion reached. If you asked a person on the street, would they not think that Lenovo is a entity of authority? That they were the ones dictating the computers configuration? That they were any more or less fallible/malicious than Sony or Microsoft or HP?

If you asked anyone, would they not follow the line of reasoning that, if the manufacturer was releasing hardware in a default state of compromise, that we could not trust the default state of released hardware? Why would you conclude the opposite after this?

I can't see a way to construe this as "We need to ensure that machines must stay as the manufacturer ordained to protect us from security threats introduced by the manufacturer!"

I don't understand the rational here.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#177

Earlier quoted context omitted.

Ding, ding, ding. ;-)

This is bumming me out. I'm really curious about what the exploit is but cannot quite put the pieces together...

I hope to have a write-up at some point in the near future. I'm working with the vendor now to fix the vulnerability and hope they will be agreeable to a co-authored write-up once they've issued patches.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#178

Earlier quoted context omitted.

Ding, ding, ding. ;-)

This is bumming me out. I'm really curious about what the exploit is but cannot quite put the pieces together...

Looks like someone already wrote a post about it: https://blog.filippo.io/komodia-superfish-ssl-validation-is-...

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#179
post #83

Earlier quoted context omitted.

the website that folks have been linking said that it didn't detect Superfish (sorry, I'm typing this from a phone) The website you're referring to, is https://canibesuperphished.com/​

Another useful website is: https://filippo.io/Badfish/

This is the one I was thinking about and implicitly referring to. Thanks for posting.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#180
post #157

Earlier quoted context omitted.

Perhaps so, but at least it would keep some of the malware out. Another option would be to put her regular use to a VM that you control (remotely) and can restore to a clean state at any time...

I'd like to see some kind of way to lock the system for older folks. I'm tired of troubleshooting my dad's computer. He doesn't even do so much as adding bookmarks, his machine exclusively browses the web. I'd like to get everything he needs installed and lock out modifications. Needs cookies obviously, but not much else. Somehow he manages to have video player issues in every single browser that I can't figure out.…

Such limitations are of course possible. Perhaps you should look up what you can achieve by running secpol.msc.

(Myself, I find that model complex and unintuitive, being used to the Unix way, but everything has its learning curve.)

Post reply on HN