Live data from Hacker News

Windows SSL Interception Gone Wild

facebook.com

71–80 of 137 posts

Re: Windows SSL Interception Gone Wild

#71
post #43
post #40

Earlier quoted context omitted.

No, if you wipe the hd and reinstall it's not an issue. I run linux because I like it. Stuff like this doesn't happen with mainstream distros.

I guess you haven't heard of amazon+ubuntu? This is just a side effect of maximizing profits, and it happens to anyone making a profit, unless they're idealistic enough.

Ubuntu wasn't MITM your connections, it's hardly the same. They had ads, not a massive security hole.

Re: Windows SSL Interception Gone Wild

#72
post #15

Earlier quoted context omitted.

I suspect flash is generally used to play sounds from chat messages - the https man-in-the-middle detection is heavily sampled, as referenced in https://www.linshunghuang.com/papers/mitm.pdf . [I work at FB, but not on sounds or directly on https man-in-the-middle detection.]

Nope, without flash you still get the chat sound messages. I've no flash on my system and the only thing that's different on facebook is that I can't watch user-uploaded videos. Only their mobile site supports HTML5 last I checked.

It is still possible that they use flash as default audio source and fallback to HTML audio if flash is unavailable. Although of course it would be better if they could get rid of the flash altogether.

Re: Windows SSL Interception Gone Wild

#73
post #43

Earlier quoted context omitted.

I guess you haven't heard of amazon+ubuntu? This is just a side effect of maximizing profits, and it happens to anyone making a profit, unless they're idealistic enough.

Ubuntu wasn't MITM your connections, it's hardly the same. They had ads, not a massive security hole.

Also they informed useres about Amazon integration and afaik provide a way to disable it.

Re: Windows SSL Interception Gone Wild

#76
post #22

I think it's interesting that this BADWARE install was found more or less accidentally... apparently by some tech dude noticing that his bank login presented a Silverfish-issued CA cert. Shouldn't the possiblity have been forseen and addressed beforehand? Perhaps by... (1) Anti-virus / anti-malware makers. Does this software not notify the user when strange CA certs are put into a system's root certificate storage? I…

I don't know where you got the idea that this got discovered accidentally by this one tech dude. Actually quite a bunch of people have been complaining online about this for months, then for some reason it blew up when the matter got the attention of the tech and sec communities.

see those for example: https://forums.lenovo.com/t5/Lenovo-P-Y-and-Z-series/Persona... http://www.thestudentroom.co.uk/showthread.php?t=3013039 https://forums.lenovo.com/t5/Lenovo-P-Y-and-Z-series/Lenovo-...

Re: Windows SSL Interception Gone Wild

#77
post #2

Just to be clear, Facebook and Google hate any software that allows users to modify content within their walled gardens (whether that's an adblock, ad injector, or other). These companies want a totally controllable user experience in order to maximize their own user metrics and monetization. My fear is that these companies will use this Superfish debacle to attack and restrict the ability for users to download legit…

Your going to get hellbanned if you keep talking like that. We love our corporate masters here.

Re: Windows SSL Interception Gone Wild

#78
post #49

Earlier quoted context omitted.

(3) Google; Chrome has a rather sophisticated mechanism for detecting MITM attacks, in that it's distributed with pinned certs for several Google properties, and phones home with reports of errors it receives. This is how the DigiNotar leak[1] was discovered. Perhaps because it was persistent and on the TCP stack level the phonehomes never succeeded? The retry logic should be robust enough to try to deliver the fraud…

Chrome does not warn if the non-official root certificate is custom installed on the local machine. It needs to do this because of the various corporate web filters and anti virus tools that MITM connections too. Maybe this is a practice that needs to stop. Malware scanners can scan on the local machine after the browser has decrypted the communication and web filtering, I think, is nothing but a sign of mistrust aga…

There are many legitimate reasons to MITM web traffic. We don't need to disallow the practice, we need to build a framework that contemplates this need and provides a robust, stable architecture for it which makes it easy to distinguish between good listeners and bad listeners.

Re: Windows SSL Interception Gone Wild

#80
post #67

Earlier quoted context omitted.

Is this documented somewhere? I tried searching for a couple combinations of "linux mint dns ad injection", but couldn't find anything relevant.

I was referring to their use of OpenDNS http://forums.linuxmint.com/viewtopic.php?f=90&t=128529 And hijacking Google search on Firefox, http://blog.linuxmint.com/?p=142

OpenDNS hasn't done ad pages for non-existent domains in ages. As for "hijacking" Google search, that's simply setting a different default - you can change it and nothing tries to stop you, and OS upgrades won't change it back (I believe).
Post reply on HN