Live data from Hacker News

Windows SSL Interception Gone Wild

facebook.com

121–130 of 137 posts

Re: Windows SSL Interception Gone Wild

#121
post #2

Just to be clear, Facebook and Google hate any software that allows users to modify content within their walled gardens (whether that's an adblock, ad injector, or other). These companies want a totally controllable user experience in order to maximize their own user metrics and monetization. My fear is that these companies will use this Superfish debacle to attack and restrict the ability for users to download legit…

> My fear is that these companies will use this Superfish debacle to attack and restrict the ability for users to download legitimate software which leverages these technologies. They already have, with HTTP/2. Encryption is mandated for HTTP/2 so something like Privoxy (or even just a caching proxy) has to use a Superfish-like method to bypass the encryption. The only alternative is to modify the browser, which they…

HTTP/2 doesn't actually require TLS (it got removed because of too many people pushing for it not being required for things like home routers and the like), though none of the major browser vendors intend on supporting HTTP/2 without it.

Re: Windows SSL Interception Gone Wild

#123

Earlier quoted context omitted.

Frankly, it's hard to keep up with all the security fail news these days (including surveillance). If it wasn't for the SIM story, I'd have missed the Five Eyes legal restraints dodge: https://plus.google.com/104092656004159577193/posts/2ncBEdPV... Via: https://news.ycombinator.com/item?id=9077061

It wasn't exactly news by the time Snowden did his dance: http://en.wikipedia.org/wiki/ECHELON

Knowing of UKUSA and Five Eyes, knowing that they share intelligence on parties OUTSIDE the member states, and knowing that they are providing one another with intelligence on each other's citizens and residents are different things.

Your Wikipedia article link doesn't directly address this. It points to several other documents though:

A 2000 ZDNet article by Duncan Campbell:

http://www.zdnet.com/article/echelon-world-under-watch-an-in...

"Under a secret agreement signed in 1947, called UKUSA, the English-speaking countries agreed to share responsibility for overseeing surveillance in different parts of the world."

That doesn't tell much. But this does:

"On 6 September 1960, two NSA defectors held a press conference and revealed the worldwide scope of NSA's activities:"

"'We know from working at NSA [that] the United States reads the secret communications of more than forty nations, including its own allies... Both enciphered and plain text communications are monitored from almost every nation in the world, including the nations on whose soil the intercept bases are located.'"

It also discusses the Church Commission hearings (1975).

I'm not sure how I'd classify this, but I see general awareness as being vastly greater. And as someone who's been paying attention to this story for a long time (15+ years), it's news to me.

Re: Windows SSL Interception Gone Wild

#124

Earlier quoted context omitted.

Adding (or removing) CAs is a fully legitimate activity. Your own site, work, or vendor / client sites could be added. Or you could want to remove a Comodo (or Honest Achmed's Used Cars and Certificates). http://www.livehacking.com/2011/04/25/honest-achmeds-used-ca... https://bugzilla.mozilla.org/show_bug.cgi?id=647959 Just because your OS / browser vendor "trusts" a cert doesn't mean you should.

Just because your OS / browser vendor "trusts" a cert doesn't mean you should. In other words, users should always have the right to control who they (indirectly) trust. That's what the comment above is referring to - it will be even worse if Superfish is used as an excuse to take away this right.

Quite right.

Re: Windows SSL Interception Gone Wild

#125
post #49

Earlier quoted context omitted.

(3) Google; Chrome has a rather sophisticated mechanism for detecting MITM attacks, in that it's distributed with pinned certs for several Google properties, and phones home with reports of errors it receives. This is how the DigiNotar leak[1] was discovered. Perhaps because it was persistent and on the TCP stack level the phonehomes never succeeded? The retry logic should be robust enough to try to deliver the fraud…

Chrome does not warn if the non-official root certificate is custom installed on the local machine. It needs to do this because of the various corporate web filters and anti virus tools that MITM connections too. Maybe this is a practice that needs to stop. Malware scanners can scan on the local machine after the browser has decrypted the communication and web filtering, I think, is nothing but a sign of mistrust aga…

Perhaps Chrome's MITM detection should only ignore private certs (for web filtering) if configured so via Group Policy or similar mechanism?

Re: Windows SSL Interception Gone Wild

#126

Earlier quoted context omitted.

Wal-Mart sold Linux machines at one time, and maybe still does. Dell does. A lot of small suppliers do (because they don't get such big OEM discounts on Windows and don't have high-volume automated production lines). But the real problem is that one "support incident" eats the profit from about five sales, or more. If you think there's a market for Linux PCs, you can always set up a company to sell them. You wouldn't…

>Dell does. Dell used to. I just contacted Dell sales and according to "Hazel" they do not offer any non-Windows OS for consumer products nor will they sell a system sans-OS. >But the real problem is that one "support incident" eats the profit from about five sales, or more. Meh, there is a lot of room for argument here. I think the real problem, after MS' many anti-competitive shenanigans is that most people just th…

> Dell used to. I just contacted Dell sales and according to "Hazel" they do not offer any non-Windows OS for consumer products nor will they sell a system sans-OS.

They do, it's called "Project Sputnik". It's targeted at developers though, which is a market that clearly makes sense, as AnthonyMouse pointed out.

http://www.dell.com/learn/us/en/555/campaigns/xps-linux-lapt...

The XPS 13 review yesterday was interesting, but I think I need a more beefy machine. Anyone has experience with this precision developer edition on Linux?

For a company specialized in Linux PCs, there is System76.

Re: Windows SSL Interception Gone Wild

#127

Earlier quoted context omitted.

It wasn't exactly news by the time Snowden did his dance: http://en.wikipedia.org/wiki/ECHELON

Knowing of UKUSA and Five Eyes, knowing that they share intelligence on parties OUTSIDE the member states , and knowing that they are providing one another with intelligence on each other's citizens and residents are different things. Your Wikipedia article link doesn't directly address this. It points to several other documents though: A 2000 ZDNet article by Duncan Campbell: http://www.zdnet.com/article/echelon-wor…

This article linked from Wikipedia has a Canadian stating that the Brits asked them to monitor British citizens and US lawmakers worrying that it was being used to spy on US citizens:

http://www.nytimes.com/library/tech/99/05/cyber/articles/27n...

I guess widespread speculation that avoiding domestic surveillance laws is one of the things done with the system isn't the same as knowing that it is going on, but my point was that the widespread speculation had proceeded Snowden by quite some time.

Re: Windows SSL Interception Gone Wild

#128

Earlier quoted context omitted.

Mozilla should just pull this plugin from addons, seriously.

What am I missing here? What makes this addon so bad? It looks like it injects buttons/overlays to show "lower" prices of items you are already viewing. While I have zero desire to install this addon I'm failing to see what it's doing that makes it deserving of being pulled.

The company is scum, as has been proven the last couple of days. I don't know why anyone (Mozillas Add-On place included) should support them and carry their software.

Re: Windows SSL Interception Gone Wild

#129

Earlier quoted context omitted.

Mozilla should just pull this plugin from addons, seriously.

What am I missing here? What makes this addon so bad? It looks like it injects buttons/overlays to show "lower" prices of items you are already viewing. While I have zero desire to install this addon I'm failing to see what it's doing that makes it deserving of being pulled.

The add-on from similarproducts.net uses superfish technology.

http://www.similarproducts.net/

> SimilarProducts is a monetization platform that uses Superfish technology to help users find and discover products visually. The technology instantly analyzes images on the web and presents identical and similar product offers.

Re: Windows SSL Interception Gone Wild

#130
post #129

Earlier quoted context omitted.

What am I missing here? What makes this addon so bad? It looks like it injects buttons/overlays to show "lower" prices of items you are already viewing. While I have zero desire to install this addon I'm failing to see what it's doing that makes it deserving of being pulled.

The add-on from similarproducts.net uses superfish technology. http://www.similarproducts.net/ > SimilarProducts is a monetization platform that uses Superfish technology to help users find and discover products visually. The technology instantly analyzes images on the web and presents identical and similar product offers.

It _is_ SuperFish, see the about page.
Post reply on HN