Live data from Hacker News

Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

bug1134506.bugzilla.mozilla.org

181–188 of 188 posts

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#182

I went to Best Buy as well today and picked up a laptop to look into this further. The Superfish software is not properly passing the validation state of the public cert when it connects to a website like Bank of America as an example. There's no need to export their private and use it in a MitM transparent proxy. The software is simply not triggering appropriate warnings when provided an obviously fake certificate t…

Article is unmarked PDF

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#183

I went to Best Buy as well today and picked up a laptop to look into this further. The Superfish software is not properly passing the validation state of the public cert when it connects to a website like Bank of America as an example. There's no need to export their private and use it in a MitM transparent proxy. The software is simply not triggering appropriate warnings when provided an obviously fake certificate t…

Article is unmarked PDF

PDF

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#185
post #159

Earlier quoted context omitted.

correct

Then it must be a simple to phrase exploit with only one obvious way of stating it.

The purpose of a publicized hash is that you can produce the content later and assert that you had authored it prior to the time you publicized the hash. This is proof to the extent that generating text to hit a given hash is really hard.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#186
post #50

Earlier quoted context omitted.

The company I work for has a strict policy of no direct outbound connections from the corporate network. This is to prevent (or just make harder) for compromised machines from "phoning home". This has the unfortunate side effect that all internet traffic must go through a proxy, they have to MiTM SSL traffic. I just use my smartphone's data for any personal internet browsing.

Well you don't have to MITM SSL in order to proxy it, it can be done in other ways. They probably choose to do so in order to see the details of the request.

btw, I took a look at google's cert in my corp network and we are getting the real one from google, so my corp is not MiTM SSL traffic from some sites right now.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#188
post #175

Earlier quoted context omitted.

I had no idea that was even an option, and I've been here for a few years now. I thought only threads could be flagged. Is comment flagging hidden from the main page to prevent accidental clicks, or its use as a "super downvote"?

It is an intentional speed-bump to cut down on reflexive flagging. Since the feature is non-obvious, I post descriptions like the above semi-regularly in the hope of getting the word out.

+1, I also had no idea this was an option until you pointed it out, I'll make sure to use it in the future. It might be helpful to perhaps add it to the HN FAQ, or some other help page that has information on "hidden" features like this one.
Post reply on HN