Browser plugins can read SSL pages no problem. So why did Superfish not just present itself like a browser plugin? Then it's just normal bloatware and probably pulls in the same profit. Some people might uninstall it is the only reason I can think why they didn't go this route. They could have pre-bundled Chrome and FF to avoid having users ok the plugin installation.
Windows SSL Interception Gone Wild
111–120 of 137 posts
Re: Windows SSL Interception Gone Wild
#112I recently bought one of these and didn't even boot it into windows before ripping out the drive and tossing in a linux installation on my SSD. Never been more grateful to be technologically competent. Also, I am wiping that drive.
Re: Windows SSL Interception Gone Wild
#113Is it just me, or is the Superfish fiasco being covered disproportionately against the other big security story this week, the NSA/GCHQ SIM heist? https://news.ycombinator.com/item?id=9076351
Frankly, it's hard to keep up with all the security fail news these days (including surveillance). If it wasn't for the SIM story, I'd have missed the Five Eyes legal restraints dodge: https://plus.google.com/104092656004159577193/posts/2ncBEdPV... Via: https://news.ycombinator.com/item?id=9077061
Re: Windows SSL Interception Gone Wild
#114Earlier quoted context omitted.
Umm, if you're using Facebook, it should be fairly obvious that you are giving your information to Facebook. Yes, I call that an informed consent.
And when you're browsing a web site with a Facebook Like button (that you don't click on), you're giving information about your browsing habits to Facebook and it's totally non-obvious.
Re: Windows SSL Interception Gone Wild
#115Earlier quoted context omitted.
Sorry, I don't understand. What does it mean that I am browsing a web site with a Facebook Like button that I don't click on?
If the button image is hosted on Facebook's servers (and it commonly is), they have a log of your request for it, including the page it was on (from the "Referer" header). This request is sent when you load the page, without the need to click on the button. Every site you visit that includes a Facebook resource gives them the ability to collect data about you and your habits. These are often part of a site's template…
Re: Windows SSL Interception Gone Wild
#116Earlier quoted context omitted.
Sorry, I don't understand. What does it mean that I am browsing a web site with a Facebook Like button that I don't click on?
If the button image is hosted on Facebook's servers (and it commonly is), they have a log of your request for it, including the page it was on (from the "Referer" header). This request is sent when you load the page, without the need to click on the button. Every site you visit that includes a Facebook resource gives them the ability to collect data about you and your habits. These are often part of a site's template…
I mean, of course elements that are embedded in Web pages may be traced by the party who sends them (and pages very often include off-site content).
Re: Windows SSL Interception Gone Wild
#117Earlier quoted context omitted.
If the button image is hosted on Facebook's servers (and it commonly is), they have a log of your request for it, including the page it was on (from the "Referer" header). This request is sent when you load the page, without the need to click on the button. Every site you visit that includes a Facebook resource gives them the ability to collect data about you and your habits. These are often part of a site's template…
It's not just an image, either. It's typically a widget that may even show you if your friends also liked the page.
Re: Windows SSL Interception Gone Wild
#118Earlier quoted context omitted.
>some OEMs have tried installing versions of Linux, with negative financial results. Which isn't much of a surprise considering what I have observed so far (in trying to purchase a Linux PC). I can't recall ever having seen an OEM offer Linux for more than a sparse subset of their product line, usually mid-tier or low-tier machines. >A few are still trying. Which ones? The situation may have changed since I last paid…
Wal-Mart sold Linux machines at one time, and maybe still does. Dell does. A lot of small suppliers do (because they don't get such big OEM discounts on Windows and don't have high-volume automated production lines). But the real problem is that one "support incident" eats the profit from about five sales, or more. If you think there's a market for Linux PCs, you can always set up a company to sell them. You wouldn't…
Dell used to. I just contacted Dell sales and according to "Hazel" they do not offer any non-Windows OS for consumer products nor will they sell a system sans-OS.
>But the real problem is that one "support incident" eats the profit from about five sales, or more.
Meh, there is a lot of room for argument here. I think the real problem, after MS' many anti-competitive shenanigans is that most people just think MS Windows is synonymous with "computer". Those who really want a Linux PC will just buy the hardware they want and install it themselves.
>If you think there's a market for Linux PCs, you can always set up a company to sell them. You wouldn't be the first to try, but you might be the first to succeed ;-)
Someone someday will probably succeed at that. I'm probably not that someone, and that day may not be today. I do think that there is a small market for it, and there could be a bigger one, maybe if/after Gaben has any success with SteamOS. OTOH, if we ever have a modular laptop standard with a commodity peripheral market then maybe not, as there would be less need. (given that the only OEM pc's I have purchased in the last 10 years were laptops).
Re: Windows SSL Interception Gone Wild
#119Earlier quoted context omitted.
> (1) Anti-virus / anti-malware makers. Does this software not notify the user when strange CA certs are put into a system's root certificate storage? I understand that certain businesses do this for traffic monitoring... so it might be legit... but still, no user notification? It was installed by the OEM. Doesn't really help if it only notifies the OEM. > (2) Microsoft. Do their license terms really allow OEMs to in…
It's not just that the OEMs wouldn't like it. The US DoJ sued Microsoft (and tried to break it up) to prevent it from having any control over what they do. In fact, Microsoft doesn't know what OEMs are installing as "Windows" unless it goes out and buys one of their PCs. Otherwise, some OEMs have tried installing versions of Linux, with negative financial results. A few are still trying. The real problems are selling…
The problem seems to be that they're always trying to put them on budget machines, which is completely the wrong market. It's chasing the customers who pinch the last penny and you're never going to make any money from them regardless. Meanwhile those customers don't know what an "Ubuntu" is but pick it because it's cheaper, and then you get overrun with support calls when they want to install Turbo Tax.
The place where it makes much more sense is the corporate and professional markets where the customers actually know what they're buying. An IT department which is just going to nuke whatever the OEM installs in favor of their own volume licensed disk image would be happy to save the cost of a [redundant] Windows license for every machine. And professionals like programmers and scientists who actually use Linux would appreciate being able to buy workstation-class hardware with official driver support.