Live data from Hacker News

Windows SSL Interception Gone Wild

facebook.com

101–110 of 137 posts

Re: Windows SSL Interception Gone Wild

#101
post #39

Earlier quoted context omitted.

You can write anywhere to disk where user has privileges (at least in FF). Not sure if that's enough. But I don't think you need a CA at all since plugins can see the full DOM (whether SSL or not). Like if you "inspect element", view source, or run firebug. The plugin is already written too: https://addons.mozilla.org/en-US/firefox/addon/windowshopper...

Mozilla should just pull this plugin from addons, seriously.

What am I missing here? What makes this addon so bad? It looks like it injects buttons/overlays to show "lower" prices of items you are already viewing. While I have zero desire to install this addon I'm failing to see what it's doing that makes it deserving of being pulled.

Re: Windows SSL Interception Gone Wild

#102
post #81

Earlier quoted context omitted.

The only way Google "needs" to collude with corporate MITM tools is its desire to court user base from corporate IT depts (allowed de jure in many countries that have weak privacy legislation). Usually Chrome is eager to show security-related notifications but for this there isn't even a yellow notification bar with "OK, got it" option.

I think this is another example of how Google clearly puts its own interests ahead of its users. Google wants to further promote it's closed Chrome ecosystem, and to do that it needs to gain corporate support, for among other things, its Chromebooks and ChromeOS platform. And it's obviously more important to appease corporate IT than to protect users security. Built in Google-spying and now, support for corporate spy…

That's a very impressive case of double think.

Google codes Chrome in order to make it more useful for various kinds of customers, such as customers who have virus scanners.

And this becomes "Google putting its own interests ahead of its users"?

Back here in reality, that's called the customer is always right and is a fundamental tenet of business.

Re: Windows SSL Interception Gone Wild

#103

Earlier quoted context omitted.

(3) Google; Chrome has a rather sophisticated mechanism for detecting MITM attacks, in that it's distributed with pinned certs for several Google properties, and phones home with reports of errors it receives. This is how the DigiNotar leak[1] was discovered. Perhaps because it was persistent and on the TCP stack level the phonehomes never succeeded? The retry logic should be robust enough to try to deliver the fraud…

> Chrome has a rather sophisticated mechanism for detecting MITM attacks Which obviously didn't work here, as Chrome was one of the most affected targets. Firefox on the other hand, was more or less absent altogether. I know which browser I will trust.

Superfish is not a man in the middle, by definition. It's running on your local computer. That's not the middle. That's the start. Consider that Superfish could have just done binary patching on the browser binaries instead of fiddling the local SSL configuration ... it's put there by the computer manufacturer so they can do anything they like.

Re: Windows SSL Interception Gone Wild

#104

Earlier quoted context omitted.

Umm, if you're using Facebook, it should be fairly obvious that you are giving your information to Facebook. Yes, I call that an informed consent.

And when you're browsing a web site with a Facebook Like button (that you don't click on), you're giving information about your browsing habits to Facebook and it's totally non-obvious.

Sorry, I don't understand. What does it mean that I am browsing a web site with a Facebook Like button that I don't click on?

Re: Windows SSL Interception Gone Wild

#105
post #22

I think it's interesting that this BADWARE install was found more or less accidentally... apparently by some tech dude noticing that his bank login presented a Silverfish-issued CA cert. Shouldn't the possiblity have been forseen and addressed beforehand? Perhaps by... (1) Anti-virus / anti-malware makers. Does this software not notify the user when strange CA certs are put into a system's root certificate storage? I…

> (1) Anti-virus / anti-malware makers. Does this software not notify the user when strange CA certs are put into a system's root certificate storage? I understand that certain businesses do this for traffic monitoring... so it might be legit... but still, no user notification? It was installed by the OEM. Doesn't really help if it only notifies the OEM. > (2) Microsoft. Do their license terms really allow OEMs to in…

It's not just that the OEMs wouldn't like it. The US DoJ sued Microsoft (and tried to break it up) to prevent it from having any control over what they do. In fact, Microsoft doesn't know what OEMs are installing as "Windows" unless it goes out and buys one of their PCs.

Otherwise, some OEMs have tried installing versions of Linux, with negative financial results. A few are still trying. The real problems are selling and supporting them.

Re: Windows SSL Interception Gone Wild

#106

Earlier quoted context omitted.

> Chrome has a rather sophisticated mechanism for detecting MITM attacks Which obviously didn't work here, as Chrome was one of the most affected targets. Firefox on the other hand, was more or less absent altogether. I know which browser I will trust.

Superfish is not a man in the middle, by definition. It's running on your local computer. That's not the middle. That's the start. Consider that Superfish could have just done binary patching on the browser binaries instead of fiddling the local SSL configuration ... it's put there by the computer manufacturer so they can do anything they like.

It's called a "man in the middle" because it intercepts connections between the source and destination. The physical location is irrelevant.

Re: Windows SSL Interception Gone Wild

#107

Earlier quoted context omitted.

> (1) Anti-virus / anti-malware makers. Does this software not notify the user when strange CA certs are put into a system's root certificate storage? I understand that certain businesses do this for traffic monitoring... so it might be legit... but still, no user notification? It was installed by the OEM. Doesn't really help if it only notifies the OEM. > (2) Microsoft. Do their license terms really allow OEMs to in…

It's not just that the OEMs wouldn't like it. The US DoJ sued Microsoft (and tried to break it up) to prevent it from having any control over what they do. In fact, Microsoft doesn't know what OEMs are installing as "Windows" unless it goes out and buys one of their PCs. Otherwise, some OEMs have tried installing versions of Linux, with negative financial results. A few are still trying. The real problems are selling…

>some OEMs have tried installing versions of Linux, with negative financial results.

Which isn't much of a surprise considering what I have observed so far (in trying to purchase a Linux PC). I can't recall ever having seen an OEM offer Linux for more than a sparse subset of their product line, usually mid-tier or low-tier machines.

>A few are still trying.

Which ones? The situation may have changed since I last paid any attention a few years ago.

>The real problems are selling and supporting them.

The MVP here is to merely accept returns for units that turned out to be particularly troublesome; which they usually do (ie: the Samsung UEFI thing from 2013).

A non-Microsoft UEFI key thing might be nice as well, but that's another story.

Re: Windows SSL Interception Gone Wild

#108

Earlier quoted context omitted.

It's not just that the OEMs wouldn't like it. The US DoJ sued Microsoft (and tried to break it up) to prevent it from having any control over what they do. In fact, Microsoft doesn't know what OEMs are installing as "Windows" unless it goes out and buys one of their PCs. Otherwise, some OEMs have tried installing versions of Linux, with negative financial results. A few are still trying. The real problems are selling…

>some OEMs have tried installing versions of Linux, with negative financial results. Which isn't much of a surprise considering what I have observed so far (in trying to purchase a Linux PC). I can't recall ever having seen an OEM offer Linux for more than a sparse subset of their product line, usually mid-tier or low-tier machines. >A few are still trying. Which ones? The situation may have changed since I last paid…

Wal-Mart sold Linux machines at one time, and maybe still does. Dell does. A lot of small suppliers do (because they don't get such big OEM discounts on Windows and don't have high-volume automated production lines). But the real problem is that one "support incident" eats the profit from about five sales, or more.

If you think there's a market for Linux PCs, you can always set up a company to sell them. You wouldn't be the first to try, but you might be the first to succeed ;-)

Re: Windows SSL Interception Gone Wild

#109

Earlier quoted context omitted.

(3) Google; Chrome has a rather sophisticated mechanism for detecting MITM attacks, in that it's distributed with pinned certs for several Google properties, and phones home with reports of errors it receives. This is how the DigiNotar leak[1] was discovered. Perhaps because it was persistent and on the TCP stack level the phonehomes never succeeded? The retry logic should be robust enough to try to deliver the fraud…

> Chrome has a rather sophisticated mechanism for detecting MITM attacks Which obviously didn't work here, as Chrome was one of the most affected targets. Firefox on the other hand, was more or less absent altogether. I know which browser I will trust.

Superfish will infect Fx also, it's just that Lenovo didn't pre-install Fx and the installer only runs once.

Re: Windows SSL Interception Gone Wild

#110

Earlier quoted context omitted.

And when you're browsing a web site with a Facebook Like button (that you don't click on), you're giving information about your browsing habits to Facebook and it's totally non-obvious.

Sorry, I don't understand. What does it mean that I am browsing a web site with a Facebook Like button that I don't click on?

If the button image is hosted on Facebook's servers (and it commonly is), they have a log of your request for it, including the page it was on (from the "Referer" header). This request is sent when you load the page, without the need to click on the button. Every site you visit that includes a Facebook resource gives them the ability to collect data about you and your habits. These are often part of a site's template, included without regard to the page it might appear on. You'd be surprised what a Referer URL can reveal about you.
Post reply on HN