Live data from Hacker News

Windows SSL Interception Gone Wild

facebook.com

21–30 of 137 posts

Re: Windows SSL Interception Gone Wild

#21

> Superfish uses a third party library from a company named Komodia to modify the Windows networking stack This is the second article I've read that states this - Superfish does no such thing.

You may find this Stackoverflow discussion interesting. Note the date.

https://stackoverflow.com/questions/16269624/the-truth-behin...

Re: Windows SSL Interception Gone Wild

#22
I think it's interesting that this BADWARE install was found more or less accidentally... apparently by some tech dude noticing that his bank login presented a Silverfish-issued CA cert.

Shouldn't the possiblity have been forseen and addressed beforehand?

Perhaps by...

(1) Anti-virus / anti-malware makers. Does this software not notify the user when strange CA certs are put into a system's root certificate storage? I understand that certain businesses do this for traffic monitoring... so it might be legit... but still, no user notification?

(2) Microsoft. Do their license terms really allow OEMs to install MiTM proxies and screw around with the root certs? Microsoft could do a good thing here by disallowing this sort of malfeasance... or is there some problem I'm not seeing with such an action?

If this were done in, say, OS X (unrealistic, of course), it would be found out and the whole tech world would know about it in a jiffy. John Siracusa would be howling at the Internet moon within a couple of hours...

Re: Windows SSL Interception Gone Wild

#23

Earlier quoted context omitted.

To be fair, I'm sure any website owner would want to prevent others from modifying their own website and how users view/interact with it.

For the ones who are pro-DRM, that is probably true; the ones who realise that trying to do that is as futile as forcing one to sit in front of the TV during the adverts, probably not. Userscripts and userstyles are very popular, and I see no particularly large backlash against them.

It's not as simple as that though. It's perfectly acceptable to want to have control over how your site is presented while still allowing your data to be accessible. If I spent a lot of time on my site UI, I wouldn't want some third party tweaking it, when that may mean I make changes to my front-end and some percentage of users break which I have no real control over. This remains true whether I replicate every capability in an open REST interface or not.

Re: Windows SSL Interception Gone Wild

#25

Ah, so this is why Facebook tries to load Flash on almost every page... Allows them to gather data like this. Always wondered why Flash was "needed". (another reason to put Flash behind click-to-play and/or push for HTML5 video)

Side note: click-to-play is a usability feature, not a security feature. It's still possible for Flash code to run before the user "clicks to play".

Re: Windows SSL Interception Gone Wild

#26

Is it just me, or is the Superfish fiasco being covered disproportionately against the other big security story this week, the NSA/GCHQ SIM heist? https://news.ycombinator.com/item?id=9076351

Maybe it's not just you, however I think a potential factor to give one more attention is that you can do something about the first, at least in the short term.

Besides cleaning your box, you can blame Lenovo, stop buying their products, promote the boycott, etc. All things that regular people can do and serves as an anger/stress/steam release valve.

The NSA news, even though it is/should be a much more important or pressing issue, it's something you "can't do anything about". I mean, ostensibly you can do a lot as a citizen, however most of those actions have long term effects and thus are not as useful as a release valve. It involves commitment and even sacrifice, whereas blaming a corporation (however righ you might be) is much more immediate and serves the purpose of having someone to blame for that and lots of other stuff, i.e. you can then blame the general state of IT security, then how the govt does nothing about it, how privay is nowadays non-existent, think of the children, etc.

I also believe another factor is the way news have found a way to tap into this need for the audience to have a release valve. Something or someone to be angry at and so all your problems can be channeled to that. Where I live I've seen a growing amount of newspapers and news media that just basically do a certain journalism that does not bring anything to the table but things to be raging about.

I guess it's easier to sell stuff when you can easily get people "on your side", and since there's always a lot of people angry at something, it becomes easy to have an audience.

So what's the point then (from the POV of the media) of bringing "important" (for different values of important) news to the front page when that would require their audience to commit to actions that would last several years (change your country's politics for example) and thus not as easily enticed to "get on your side" (and thus buy your media), if on the other hand you could bring, I guess you could call them "anger-bait" (like click-bait) news, and have everyone talk about it by virtue of functioning as an escape valve where people relieve their stress, fear, anger, etc?

I'm not saying it's a good thing, but I've seen more and more evidence that points in this direction, and I guess that would be my answer as to why one has much more attention than the other.

Edit:

As an analogy, I read somewhere about the recent Charlie Hebdo (sp?) attack and how it got disproportionate attention vs the two thousand killed by ISIS (I believe it was ISIS... or Borok Haram?). Maybe it's a similar thing. You believe you are able to do "more" when it's close to home (Western nation) vs far (somewhere in Africa, far away from me).

Re: Windows SSL Interception Gone Wild

#27

Ah, so this is why Facebook tries to load Flash on almost every page... Allows them to gather data like this. Always wondered why Flash was "needed". (another reason to put Flash behind click-to-play and/or push for HTML5 video)

Side note: click-to-play is a usability feature, not a security feature. It's still possible for Flash code to run before the user "clicks to play".

Er, are you sure about that? That doesn't appear to be the case with Firefox.

Re: Windows SSL Interception Gone Wild

#28
post #20

we see several reasons to be concerned about this practice in the case of Superfish and others. Chief among those is privacy—the Superfish software can see all of the computer user's activity, including banking, email and Facebook traffic. Never mind that Facebook sees all the computer user's Facebook traffic, and cross-indexes it with every other bit of data gleaned from their vast graph and uses it for profit.

Yes, and they do all that with the user's consent.

Re: Windows SSL Interception Gone Wild

#30

Is it just me, or is the Superfish fiasco being covered disproportionately against the other big security story this week, the NSA/GCHQ SIM heist? https://news.ycombinator.com/item?id=9076351

Frankly, it's hard to keep up with all the security fail news these days (including surveillance).

If it wasn't for the SIM story, I'd have missed the Five Eyes legal restraints dodge:

https://plus.google.com/104092656004159577193/posts/2ncBEdPV...

Via: https://news.ycombinator.com/item?id=9077061

Post reply on HN