Earlier quoted context omitted.
You can write anywhere to disk where user has privileges (at least in FF). Not sure if that's enough. But I don't think you need a CA at all since plugins can see the full DOM (whether SSL or not). Like if you "inspect element", view source, or run firebug. The plugin is already written too: https://addons.mozilla.org/en-US/firefox/addon/windowshopper...
Mozilla should just pull this plugin from addons, seriously.
Windows SSL Interception Gone Wild
101–110 of 137 posts
Re: Windows SSL Interception Gone Wild
#102Earlier quoted context omitted.
The only way Google "needs" to collude with corporate MITM tools is its desire to court user base from corporate IT depts (allowed de jure in many countries that have weak privacy legislation). Usually Chrome is eager to show security-related notifications but for this there isn't even a yellow notification bar with "OK, got it" option.
I think this is another example of how Google clearly puts its own interests ahead of its users. Google wants to further promote it's closed Chrome ecosystem, and to do that it needs to gain corporate support, for among other things, its Chromebooks and ChromeOS platform. And it's obviously more important to appease corporate IT than to protect users security. Built in Google-spying and now, support for corporate spy…
Google codes Chrome in order to make it more useful for various kinds of customers, such as customers who have virus scanners.
And this becomes "Google putting its own interests ahead of its users"?
Back here in reality, that's called the customer is always right and is a fundamental tenet of business.
Re: Windows SSL Interception Gone Wild
#103Earlier quoted context omitted.
(3) Google; Chrome has a rather sophisticated mechanism for detecting MITM attacks, in that it's distributed with pinned certs for several Google properties, and phones home with reports of errors it receives. This is how the DigiNotar leak[1] was discovered. Perhaps because it was persistent and on the TCP stack level the phonehomes never succeeded? The retry logic should be robust enough to try to deliver the fraud…
> Chrome has a rather sophisticated mechanism for detecting MITM attacks Which obviously didn't work here, as Chrome was one of the most affected targets. Firefox on the other hand, was more or less absent altogether. I know which browser I will trust.
Re: Windows SSL Interception Gone Wild
#104Earlier quoted context omitted.
Umm, if you're using Facebook, it should be fairly obvious that you are giving your information to Facebook. Yes, I call that an informed consent.
And when you're browsing a web site with a Facebook Like button (that you don't click on), you're giving information about your browsing habits to Facebook and it's totally non-obvious.
Re: Windows SSL Interception Gone Wild
#105I think it's interesting that this BADWARE install was found more or less accidentally... apparently by some tech dude noticing that his bank login presented a Silverfish-issued CA cert. Shouldn't the possiblity have been forseen and addressed beforehand? Perhaps by... (1) Anti-virus / anti-malware makers. Does this software not notify the user when strange CA certs are put into a system's root certificate storage? I…
> (1) Anti-virus / anti-malware makers. Does this software not notify the user when strange CA certs are put into a system's root certificate storage? I understand that certain businesses do this for traffic monitoring... so it might be legit... but still, no user notification? It was installed by the OEM. Doesn't really help if it only notifies the OEM. > (2) Microsoft. Do their license terms really allow OEMs to in…
Otherwise, some OEMs have tried installing versions of Linux, with negative financial results. A few are still trying. The real problems are selling and supporting them.
Re: Windows SSL Interception Gone Wild
#106Earlier quoted context omitted.
> Chrome has a rather sophisticated mechanism for detecting MITM attacks Which obviously didn't work here, as Chrome was one of the most affected targets. Firefox on the other hand, was more or less absent altogether. I know which browser I will trust.
Superfish is not a man in the middle, by definition. It's running on your local computer. That's not the middle. That's the start. Consider that Superfish could have just done binary patching on the browser binaries instead of fiddling the local SSL configuration ... it's put there by the computer manufacturer so they can do anything they like.
Re: Windows SSL Interception Gone Wild
#107Earlier quoted context omitted.
> (1) Anti-virus / anti-malware makers. Does this software not notify the user when strange CA certs are put into a system's root certificate storage? I understand that certain businesses do this for traffic monitoring... so it might be legit... but still, no user notification? It was installed by the OEM. Doesn't really help if it only notifies the OEM. > (2) Microsoft. Do their license terms really allow OEMs to in…
It's not just that the OEMs wouldn't like it. The US DoJ sued Microsoft (and tried to break it up) to prevent it from having any control over what they do. In fact, Microsoft doesn't know what OEMs are installing as "Windows" unless it goes out and buys one of their PCs. Otherwise, some OEMs have tried installing versions of Linux, with negative financial results. A few are still trying. The real problems are selling…
Which isn't much of a surprise considering what I have observed so far (in trying to purchase a Linux PC). I can't recall ever having seen an OEM offer Linux for more than a sparse subset of their product line, usually mid-tier or low-tier machines.
>A few are still trying.
Which ones? The situation may have changed since I last paid any attention a few years ago.
>The real problems are selling and supporting them.
The MVP here is to merely accept returns for units that turned out to be particularly troublesome; which they usually do (ie: the Samsung UEFI thing from 2013).
A non-Microsoft UEFI key thing might be nice as well, but that's another story.
Re: Windows SSL Interception Gone Wild
#108Earlier quoted context omitted.
It's not just that the OEMs wouldn't like it. The US DoJ sued Microsoft (and tried to break it up) to prevent it from having any control over what they do. In fact, Microsoft doesn't know what OEMs are installing as "Windows" unless it goes out and buys one of their PCs. Otherwise, some OEMs have tried installing versions of Linux, with negative financial results. A few are still trying. The real problems are selling…
>some OEMs have tried installing versions of Linux, with negative financial results. Which isn't much of a surprise considering what I have observed so far (in trying to purchase a Linux PC). I can't recall ever having seen an OEM offer Linux for more than a sparse subset of their product line, usually mid-tier or low-tier machines. >A few are still trying. Which ones? The situation may have changed since I last paid…
If you think there's a market for Linux PCs, you can always set up a company to sell them. You wouldn't be the first to try, but you might be the first to succeed ;-)
Re: Windows SSL Interception Gone Wild
#109Earlier quoted context omitted.
(3) Google; Chrome has a rather sophisticated mechanism for detecting MITM attacks, in that it's distributed with pinned certs for several Google properties, and phones home with reports of errors it receives. This is how the DigiNotar leak[1] was discovered. Perhaps because it was persistent and on the TCP stack level the phonehomes never succeeded? The retry logic should be robust enough to try to deliver the fraud…
> Chrome has a rather sophisticated mechanism for detecting MITM attacks Which obviously didn't work here, as Chrome was one of the most affected targets. Firefox on the other hand, was more or less absent altogether. I know which browser I will trust.
Re: Windows SSL Interception Gone Wild
#110Earlier quoted context omitted.
And when you're browsing a web site with a Facebook Like button (that you don't click on), you're giving information about your browsing habits to Facebook and it's totally non-obvious.
Sorry, I don't understand. What does it mean that I am browsing a web site with a Facebook Like button that I don't click on?