Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
181–188 of 188 posts
Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#182I went to Best Buy as well today and picked up a laptop to look into this further. The Superfish software is not properly passing the validation state of the public cert when it connects to a website like Bank of America as an example. There's no need to export their private and use it in a MitM transparent proxy. The software is simply not triggering appropriate warnings when provided an obviously fake certificate t…
Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#183I went to Best Buy as well today and picked up a laptop to look into this further. The Superfish software is not properly passing the validation state of the public cert when it connects to a website like Bank of America as an example. There's no need to export their private and use it in a MitM transparent proxy. The software is simply not triggering appropriate warnings when provided an obviously fake certificate t…
Article is unmarked PDF
Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#184Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#185Earlier quoted context omitted.
correct
Then it must be a simple to phrase exploit with only one obvious way of stating it.
Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#186Earlier quoted context omitted.
The company I work for has a strict policy of no direct outbound connections from the corporate network. This is to prevent (or just make harder) for compromised machines from "phoning home". This has the unfortunate side effect that all internet traffic must go through a proxy, they have to MiTM SSL traffic. I just use my smartphone's data for any personal internet browsing.
Well you don't have to MITM SSL in order to proxy it, it can be done in other ways. They probably choose to do so in order to see the details of the request.
Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#187Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#188Earlier quoted context omitted.
I had no idea that was even an option, and I've been here for a few years now. I thought only threads could be flagged. Is comment flagging hidden from the main page to prevent accidental clicks, or its use as a "super downvote"?
It is an intentional speed-bump to cut down on reflexive flagging. Since the feature is non-obvious, I post descriptions like the above semi-regularly in the hope of getting the word out.