Live data from Hacker News

Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

bug1134506.bugzilla.mozilla.org

161–170 of 188 posts

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#161
post #90

While this whole Superfish/Lenovo thing is certainly quite scary, let's not forget the very important fact that, currently, the user ultimately still has the ability to modify the software on the machines he/she owns, which includes among other things (un)installing software like Superfish, and also adding/removing trusted certificates. There will be those who advocate locking down the certificate stores and other ar…

I'm very hesitant to use this word, but this is a very privileged position. Many customers don't have the skills to even see the technical problem while expecting that not to happen. The same goes for reinstalling the machine (or they don't trust in their skills).

Do we stop allowing home loans because the majority of those signing them honestly don't most of those clauses? Do we ban cell phone contracts because only 1 in 100 even read what they are signing?

I think that it is a very life altering precedent to say we ban adults from consenting to things because they don't know what they are consenting to. Maybe one that is needed, but it would be far reaching if consistently applied.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#162
post #4

This is a PDF attached to this issue, requesting blacklisting of the Superfish certificate: https://bugzilla.mozilla.org/show_bug.cgi?id=1134506

Isn't this the sort of thing that Microsoft should be removing with the malicious software removal tool as well?

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#163

Earlier quoted context omitted.

These guys aren't the brightest bulbs out there. You could even have it switch certificates on every reboot... or not do this in the first place. ;-)

> or not to do this in the first place. Are there other options besides installing my own root certificate? Assuming I want to write software that legitimately MITMs all HTTP and HTTPS traffic (parental control, ad blocker, anti-virus scan for webpages...). I want it to be browser independent and work with browsers that don't support extensions.

It's fine to proxy HTTPS.

But when you do so, you assume big responsibilities. You have to do all the stuff the browser does, and even lots of security people, if you sat them down and told them to write everything a browser does, would probably forget a few important things. (The browser security folks are exceptions.)

The top post on this page ('patcheudor) is from a researcher who reports that Superfish wasn't doing proper validation of certs, meaning we didn't even need to extract the private key from the binary to forge www.paypal.com.

If I spun up a stupid fake cert for www.paypal.com last week, with no knowledge of Superfish whatsoever, someone from a Lenovo computer would not get certificate warnings.

The more people look at this, the worse it gets. It's a fractal of bad security.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#164
post #28

I originally discovered this issue a month ago when debugging my friend's Lenovo laptop. Neither chrome nor IE can render battle.net correctly because the HTML injection is not properly escaped. Since the problem persists after a fresh recovery, I guess it's from some pre-installed software. I almost reported it to FBI.

Shouldn't Lenovo be guilty of hacking and illegal wiretaps?

The law that would make this criminal would probably make innocently shipping software with security holes criminal as well.

(There are some people in the industry who call for this. I am not one of them.)

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#165
post #29
post #17

Earlier quoted context omitted.

Chrome does do pinning, but ignores pins when the cert parent is a privately installed cert (because this is a "feature" used by many enterprises). """ Chrome does not perform pin validation when the certificate chain chains up to a private trust anchor. A key result of this policy is that private trust anchors can be used to proxy (or MITM) connections, even to pinned sites. 'Data loss prevention' appliances, firewa…

TIL Google is ok if you get backdoored by your boss.

If it's my boss's machine, yes, my boss gets to do it.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#166
post #90

Earlier quoted context omitted.

I'm very hesitant to use this word, but this is a very privileged position. Many customers don't have the skills to even see the technical problem while expecting that not to happen. The same goes for reinstalling the machine (or they don't trust in their skills).

Do we stop allowing home loans because the majority of those signing them honestly don't most of those clauses? Do we ban cell phone contracts because only 1 in 100 even read what they are signing? I think that it is a very life altering precedent to say we ban adults from consenting to things because they don't know what they are consenting to. Maybe one that is needed, but it would be far reaching if consistently a…

> I think that it is a very life altering precedent to say we ban adults from consenting to things because they don't know what they are consenting to.

Just going off your examples, I don't think it would be unreasonable to require both parties entering into a contract to understand what they are agreeing to. I'd say anything else is unethical, really.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#167
post #90

Earlier quoted context omitted.

I'm very hesitant to use this word, but this is a very privileged position. Many customers don't have the skills to even see the technical problem while expecting that not to happen. The same goes for reinstalling the machine (or they don't trust in their skills).

Do we stop allowing home loans because the majority of those signing them honestly don't most of those clauses? Do we ban cell phone contracts because only 1 in 100 even read what they are signing? I think that it is a very life altering precedent to say we ban adults from consenting to things because they don't know what they are consenting to. Maybe one that is needed, but it would be far reaching if consistently a…

In EU we do have laws that make unreasonable contracts unlawful. This sits with "buyer beware". A buyer should take efforts to learn about the contract they're entering into, but supplier can't hide onerous terms deep in a complex contract and say that they warned the buyer.

> I think that it is a very life altering precedent to say we ban adults from consenting to things because they don't know what they are consenting to.

We already have this in "informed consent" - the permission a patient gives for medical intervention. The consent has to be voluntary and made after being informed - in a way the patient can understand - about the risks and potential harms as well as the benefits.

We also (at least, in England) have regulated advertising ("legal, decent, honest, and truthful") and strict consumer protection laws.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#168
post #90

Earlier quoted context omitted.

I'm very hesitant to use this word, but this is a very privileged position. Many customers don't have the skills to even see the technical problem while expecting that not to happen. The same goes for reinstalling the machine (or they don't trust in their skills).

Do we stop allowing home loans because the majority of those signing them honestly don't most of those clauses? Do we ban cell phone contracts because only 1 in 100 even read what they are signing? I think that it is a very life altering precedent to say we ban adults from consenting to things because they don't know what they are consenting to. Maybe one that is needed, but it would be far reaching if consistently a…

In EU we do have laws that make unreasonable contracts unlawful. This sits with "buyer beware". A buyer should take efforts to learn about the contract they're entering into, but supplier can't hide onerous terms deep in a complex contract and say that they warned the buyer.

> I think that it is a very life altering precedent to say we ban adults from consenting to things because they don't know what they are consenting to.

We already have this in "informed consent" - the permission a patient gives for medical intervention. The consent has to be voluntary and made after being informed - in a way the patient can understand - about the risks and potential harms as well as the benefits.

We also (at least, in England) have regulated advertising ("legal, decent, honest, and truthful") and strict consumer protection laws.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#169
post #85

Earlier quoted context omitted.

Use some software with which you can do remote maintenance on your parents' computer(s). Or, introduce them to more stable OSses, like Ubuntu instead of Windows. That worked for my neighbours ;-)

I've thought about Ubuntu...but it's a comfort thing. I'm afraid that telling my parents "hey so this new thing is more stable...." and it'll just trail off after that. For now, I'm afraid, I'll just keep fighting the good fight. Remote maintenance is probably something I should look more into.

Personal experience: my mother runs a Thinkpad T400 with Lubuntu and manages just fine. For many people, the look of the operating system doesn't matter much. As long as she knows where to open the browser and the email client, she's good.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#170
post #90

Earlier quoted context omitted.

I'm very hesitant to use this word, but this is a very privileged position. Many customers don't have the skills to even see the technical problem while expecting that not to happen. The same goes for reinstalling the machine (or they don't trust in their skills).

Do we stop allowing home loans because the majority of those signing them honestly don't most of those clauses? Do we ban cell phone contracts because only 1 in 100 even read what they are signing? I think that it is a very life altering precedent to say we ban adults from consenting to things because they don't know what they are consenting to. Maybe one that is needed, but it would be far reaching if consistently a…

This is standard in the EU and I think that is a good thing.

Full contractual freedom is a B2B thing here.

And yes, having people sign that their communication will be monitored is an unreasonable thing in my opinion, cutting to the core of constitutional rights e.g. in Germany.

While we are at that, Germany has a constitutional right of privacy in your place of living - which is in an interesting juxtaposition to devices listening to what happens in your living room and sending it somewhere.

And finally, there is a non-negligible part of the population that cannot grasp those contracts - expecting them to keep track of all the things they signed in their life is an extreme burden.

Post reply on HN