Live data from Hacker News

Windows SSL Interception Gone Wild

facebook.com

11–20 of 137 posts

Re: Windows SSL Interception Gone Wild

#11

> Superfish uses a third party library from a company named Komodia to modify the Windows networking stack This is the second article I've read that states this - Superfish does no such thing.

How do you know one way or the other? Care to enlighten us?

Re: Windows SSL Interception Gone Wild

#12

> Superfish uses a third party library from a company named Komodia to modify the Windows networking stack This is the second article I've read that states this - Superfish does no such thing.

What doesn't it do? It is modifying the network stack by intercepting all traffic (presumably through a proxy), right?

Re: Windows SSL Interception Gone Wild

#13

> Superfish uses a third party library from a company named Komodia to modify the Windows networking stack This is the second article I've read that states this - Superfish does no such thing.

My (not very studied) understanding is that it used SSL Digestor:

https://web.archive.org/web/20150220003144/http://www.komodi...

installed as a LSP:

http://en.wikipedia.org/wiki/Layered_Service_Provider

"modify the windows networking stack" is not an absurd description of that.

Re: Windows SSL Interception Gone Wild

#14
post #2

Just to be clear, Facebook and Google hate any software that allows users to modify content within their walled gardens (whether that's an adblock, ad injector, or other). These companies want a totally controllable user experience in order to maximize their own user metrics and monetization. My fear is that these companies will use this Superfish debacle to attack and restrict the ability for users to download legit…

To be fair, I'm sure any website owner would want to prevent others from modifying their own website and how users view/interact with it.

Re: Windows SSL Interception Gone Wild

#15

Ah, so this is why Facebook tries to load Flash on almost every page... Allows them to gather data like this. Always wondered why Flash was "needed". (another reason to put Flash behind click-to-play and/or push for HTML5 video)

I suspect flash is generally used to play sounds from chat messages - the https man-in-the-middle detection is heavily sampled, as referenced in https://www.linshunghuang.com/papers/mitm.pdf.

[I work at FB, but not on sounds or directly on https man-in-the-middle detection.]

Re: Windows SSL Interception Gone Wild

#16
post #2

Just to be clear, Facebook and Google hate any software that allows users to modify content within their walled gardens (whether that's an adblock, ad injector, or other). These companies want a totally controllable user experience in order to maximize their own user metrics and monetization. My fear is that these companies will use this Superfish debacle to attack and restrict the ability for users to download legit…

[deleted]

Re: Windows SSL Interception Gone Wild

#18
post #2

Just to be clear, Facebook and Google hate any software that allows users to modify content within their walled gardens (whether that's an adblock, ad injector, or other). These companies want a totally controllable user experience in order to maximize their own user metrics and monetization. My fear is that these companies will use this Superfish debacle to attack and restrict the ability for users to download legit…

To be fair, I'm sure any website owner would want to prevent others from modifying their own website and how users view/interact with it.

For the ones who are pro-DRM, that is probably true; the ones who realise that trying to do that is as futile as forcing one to sit in front of the TV during the adverts, probably not.

Userscripts and userstyles are very popular, and I see no particularly large backlash against them.

Re: Windows SSL Interception Gone Wild

#19

Ah, so this is why Facebook tries to load Flash on almost every page... Allows them to gather data like this. Always wondered why Flash was "needed". (another reason to put Flash behind click-to-play and/or push for HTML5 video)

I don't follow why this upsets you. Seems like an argument for why allowing flash to run can be used for good?

Re: Windows SSL Interception Gone Wild

#20
we see several reasons to be concerned about this practice in the case of Superfish and others. Chief among those is privacy—the Superfish software can see all of the computer user's activity, including banking, email and Facebook traffic.

Never mind that Facebook sees all the computer user's Facebook traffic, and cross-indexes it with every other bit of data gleaned from their vast graph and uses it for profit.

Post reply on HN