Live data from Hacker News

Windows SSL Interception Gone Wild

facebook.com

1–10 of 137 posts

Re: Windows SSL Interception Gone Wild

#2
Just to be clear, Facebook and Google hate any software that allows users to modify content within their walled gardens (whether that's an adblock, ad injector, or other). These companies want a totally controllable user experience in order to maximize their own user metrics and monetization.

My fear is that these companies will use this Superfish debacle to attack and restrict the ability for users to download legitimate software which leverages these technologies. As users and developers, we want to retain this ability.

Adware sucks, and there are dozens of anti-virus companies who should be all over anyone who tries to pull this crap. The problem here is not with MITM, SSL packet inspection or modification. The problem here is that Lenovo allowed themselves to be turned into a distribution channel for a poorly implemented, spammy piece of adware for a few extra pennies.

Re: Windows SSL Interception Gone Wild

#4
post #2

Just to be clear, Facebook and Google hate any software that allows users to modify content within their walled gardens (whether that's an adblock, ad injector, or other). These companies want a totally controllable user experience in order to maximize their own user metrics and monetization. My fear is that these companies will use this Superfish debacle to attack and restrict the ability for users to download legit…

I'm not sure why a normal user would ever need to add CAs to their root store. Can you clarify?

Re: Windows SSL Interception Gone Wild

#5
post #4
post #2

Just to be clear, Facebook and Google hate any software that allows users to modify content within their walled gardens (whether that's an adblock, ad injector, or other). These companies want a totally controllable user experience in order to maximize their own user metrics and monetization. My fear is that these companies will use this Superfish debacle to attack and restrict the ability for users to download legit…

I'm not sure why a normal user would ever need to add CAs to their root store. Can you clarify?

Realizing an adblock mechanism, for one. (Similar to InterMute in late 90s, and admucher.com now.)

Re: Windows SSL Interception Gone Wild

#7
post #4
post #2

Just to be clear, Facebook and Google hate any software that allows users to modify content within their walled gardens (whether that's an adblock, ad injector, or other). These companies want a totally controllable user experience in order to maximize their own user metrics and monetization. My fear is that these companies will use this Superfish debacle to attack and restrict the ability for users to download legit…

I'm not sure why a normal user would ever need to add CAs to their root store. Can you clarify?

Depends on what you mean by "normal user." It's somewhat advanced, for sure, but many companies use private CAs to issue certs for their intranet sites, and the ability to install those certs on client machines is very useful.

Re: Windows SSL Interception Gone Wild

#8
post #4
post #2

Just to be clear, Facebook and Google hate any software that allows users to modify content within their walled gardens (whether that's an adblock, ad injector, or other). These companies want a totally controllable user experience in order to maximize their own user metrics and monetization. My fear is that these companies will use this Superfish debacle to attack and restrict the ability for users to download legit…

I'm not sure why a normal user would ever need to add CAs to their root store. Can you clarify?

Plenty of enterprise users need to. There are other reasons too.

I presume 'nugget is talking about the HTML rewriting aspect of the software. Injecting additional/unwanted tracking code == bad, user-requested re-writing of content == good.

Post reply on HN