Live data from Hacker News

Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

bug1134506.bugzilla.mozilla.org

141–150 of 188 posts

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#141
post #79

Earlier quoted context omitted.

They definitely can blacklist the certificate. They have the choice of having HTTPS effectively useless (by leaving the certificate there), or making HTTPS not work (by removing it, thus prompting action from the user to fix it -- perhaps by calling their tech savvy nephew). Browser vendors should (and usually do) err on the side of security.

Or the users just switch to a browser that works. IE or Chrome :(

Most Firefox users switched away from those (or didn't switch to them) because it works better for them - including security wise. I suspect that won't be their first course of action.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#142

Earlier quoted context omitted.

Well, perhaps it would be good to give her a non-admin account to Windows? The same approach you'd do with a Mac, but leaving her with a familiar UI.

Privilege escalation, even with UAC at its strictest, is trivial on Windows with the malware that's floating around these days. I worked full time for 5 of the last 6 years on Windows malware research. Windows is a swiss-cheese joke of an operating system that won't progress because of a(n at this point pathological) need for 20 years of backwards compatibility. Microsoft: make use of that XP mode VM and extend that…

Perhaps so, but at least it would keep some of the malware out.

Another option would be to put her regular use to a VM that you control (remotely) and can restore to a clean state at any time...

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#143

Computing is genuinely becoming scary. If I didn't browse tech sites or spend my days on HackerNews, I probably wouldn't know about these things. I'm getting older and more disinterested in the constant maintenance -- I just want the shit to work. It sucks the most for those who learned "don't install anything fishy, run a virus scan, don't open attachments, and you'll be fine." They bought a computer and followed th…

Yes, this is a huge issue. We in the technical community will take the extra steps. We will reformat a system and install a new o/s. We will go through the steps to remove malware/adware. We will install our own web browsers and additional security software. We'll use VPNs. We'll use PGP keys. We'll use Tor.

But the "regular" users won't. It's not that they _can't_. It's just that for them Internet-connected computers are just tools. Tools to get to information and services... or to get their jobs done. They don't want to mess around with systems - they just want to order something online or communicate with family and friends.

And they are buying laptops like these because they are inexpensive and seem to fit their needs. They just want a tool they can use.

They are _trusting_ Lenovo and other manufacturers. And that trust is being betrayed.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#144
post #132
post #90

Earlier quoted context omitted.

I'm very hesitant to use this word, but this is a very privileged position. Many customers don't have the skills to even see the technical problem while expecting that not to happen. The same goes for reinstalling the machine (or they don't trust in their skills).

Perhaps not, but such customers CAN purchase software written by someone who DOES have the skills, that will perform the actions on their behalf. If the machine is locked down to prevent that, then the customers have no such option.

Grandma just bought her laptop from the fine folks at Best Buy. They obviously know best, and why would the sell her a computer in less the pristine condition? It's fine as is, she doesn't know to or have to pay someone to fix something that should be ok.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#145
post #28

Earlier quoted context omitted.

Shouldn't Lenovo be guilty of hacking and illegal wiretaps?

To be guilty of wire fraud, Lenovo must have intent to defraud the user out of money. It will be tricky to prosecutte.

Placing their ads on a site where the user believes they are something else (e.g. Google search ads) has to qualify.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#146
post #66

Earlier quoted context omitted.

From what I understand of Superfish, Mozilla (and other browser vendors) can't just blacklist the certificate. That would make all HTTPS connections error out. A message notifying users of the issue is all they can do.

One way would be to bypass the proxy if it's detected as a Superfish proxy by its certificate, but somehow I feel like this isn't a problem the browser vendors should be doing extra workarounds for (and giving precedence to "if we don't like your proxy we'll ignore it" isn't a great idea either.)

It doesn't appear to be implemented as a user visible proxy, it modifies the network stack. From:

https://twitter.com/matthew_d_green/status/56843703790644428...

Probably not a proxy; probably low-level socket interception in Windows.

So there isn't much the browsers can do to help the user.

At least the technical side of Lenovo's response is all the way to "We are writing a program to remove the certificates", which is probably the thing that is going to impact the most people.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#147
post #110

Earlier quoted context omitted.

Correct, the firewall intercepts all traffic looking for potential compromises and blocks it. Given all these corporations getting hacked, such measures seem necessary.

Conclusion does not follow from premise. Once an attacker's code is running on machines that have access to sensitive data, you've already lost - there's no way to prevent it smuggling the data out in legitimate-looking requests. The right way is to stop the bad stuff getting in in the first place.

Not all attacks are perfect. It's true that an attacker can potentially do anything once in control of machines with sensitive data, but it doesn't mean that all hope is lost. If an intrusion detection system catches some x% of potential threats, it can easily be worth it.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#148

While this whole Superfish/Lenovo thing is certainly quite scary, let's not forget the very important fact that, currently, the user ultimately still has the ability to modify the software on the machines he/she owns, which includes among other things (un)installing software like Superfish, and also adding/removing trusted certificates. There will be those who advocate locking down the certificate stores and other ar…

The problem with whiping a brand new computer and installing your own will not necessarily void warranty but if you have a problem like something is not working, technical support will tell you to restore the system.

Many new systems now don't even come with original software disks requiring you to backup the machine using preinstalled crapware to create a backup DVD.

This was the case with a couple of laptops I purchased in the past three years; one of which was a Toshiba.

Years ago, when you purchased a machine, you got driver disk separately and even now I'm seeing a trend where that's becoming less the case.

At least this has been my experience.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#149

Earlier quoted context omitted.

This. I can tell several stories of trying to set things up for my parents, only to have to call them/wait until I fly home next to fix something. Lessons have been learned the hard way on dumb email chains/anti-virus software, but trying to give them a list of browser settings (among other things) to do is getting to be too much. So, now what?

I'm in this situation too. We're at an impasse now too where my mom wants a new laptop. She doesn't want to learn anything new (Mac OS) and both she and I don't want to deal with Windows 8+. I'm skeptical about just installing Windows 7 on a newer laptop (...driver/hardware support). If I could get her to switch to Mac (she's in her 70s), I could set her up with a non-admin user account and set it up easily so that I…

same situation here. I convinced my mother to just get an Android based tablet and ditch the laptop. This seems to be working better for her & me :)

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#150
post #132
post #90

Earlier quoted context omitted.

I'm very hesitant to use this word, but this is a very privileged position. Many customers don't have the skills to even see the technical problem while expecting that not to happen. The same goes for reinstalling the machine (or they don't trust in their skills).

Perhaps not, but such customers CAN purchase software written by someone who DOES have the skills, that will perform the actions on their behalf. If the machine is locked down to prevent that, then the customers have no such option.

If you buy a new car, are you okay to have to bring it to another shop immediately? If yes, did you factor in that cost?

Do you know that you have to?

How do you, with no software skills at all, evaluate whether the second person you bring it to does have the skills?

Post reply on HN