Live data from Hacker News

Windows SSL Interception Gone Wild

facebook.com

91–100 of 137 posts

Re: Windows SSL Interception Gone Wild

#91
post #81
post #49

Earlier quoted context omitted.

Chrome does not warn if the non-official root certificate is custom installed on the local machine. It needs to do this because of the various corporate web filters and anti virus tools that MITM connections too. Maybe this is a practice that needs to stop. Malware scanners can scan on the local machine after the browser has decrypted the communication and web filtering, I think, is nothing but a sign of mistrust aga…

The only way Google "needs" to collude with corporate MITM tools is its desire to court user base from corporate IT depts (allowed de jure in many countries that have weak privacy legislation). Usually Chrome is eager to show security-related notifications but for this there isn't even a yellow notification bar with "OK, got it" option.

I think this is another example of how Google clearly puts its own interests ahead of its users.

Google wants to further promote it's closed Chrome ecosystem, and to do that it needs to gain corporate support, for among other things, its Chromebooks and ChromeOS platform.

And it's obviously more important to appease corporate IT than to protect users security.

Built in Google-spying and now, support for corporate spying too? I wouldn't trust a Chromebook as far as I can throw it.

Re: Windows SSL Interception Gone Wild

#92
But this problem is not only about CA certs. If the application sits in the same computer it can intercept the SSL libs used in the application (wininet for IE, and the Firefox and Chrome used libs) to watch and modify SSL connections.

This can be done without any proxy or certificate installation.

Re: Windows SSL Interception Gone Wild

#93

Earlier quoted context omitted.

Um, really? How informed is that consent? What of sites that unilaterally change rules retroactively? Or fail to provide reasonable alternatives? Facebook does all of the above. To an extent that I don't trust it, and don't use it. But there are plenty of other services which wave the "but you consented!" flag. Google comes to mind, and I've had my set of issues with them as well.

Umm, if you're using Facebook, it should be fairly obvious that you are giving your information to Facebook. Yes, I call that an informed consent.

And when you're browsing a web site with a Facebook Like button (that you don't click on), you're giving information about your browsing habits to Facebook and it's totally non-obvious.

Re: Windows SSL Interception Gone Wild

#95

I recently bought one of these and didn't even boot it into windows before ripping out the drive and tossing in a linux installation on my SSD. Never been more grateful to be technologically competent. Also, I am wiping that drive.

You're the Chuck Norris of HN

Too edgy for me :)

Re: Windows SSL Interception Gone Wild

#96

Holy shit, I bought a lenovo Z50-70, ripped out my drive, and put in a linux drive. I've never been happier to have some semblance of control over these things.

You do realize.. ..that you can just re-format your drive as it is.

One week ago the HDD firmware manipulation by NSA/GCHQ was revealed. So, if the snoops intercept the parcel with the laptop, it's better when you go into a computer parts store and buy a random HDD...

Re: Windows SSL Interception Gone Wild

#98
post #84

Earlier quoted context omitted.

web filtering, I think, is nothing but a sign of mistrust against the users. What if it's the user who wants this filtering? I run a local proxy that MITMs to filter out ads, tracking scripts, and other undesirable things. It works in all the browsers I use regularly, and any browsers that happen to be embedded in apps, because this way the stuff I want filtered out never even reaches the browser.

Can you please tell more about your setup? Why a handful of browser plugins were not enough in your case?

Filtering reverse proxies e.g. privoxy have an advantage over browser plugins as they work on the network level instead on the DOM. This means that it work as an universal adblock regardless of what OS or browser you are running. It's especially useful when you are on mobile safari or chrome as they don't support adblocks.

Re: Windows SSL Interception Gone Wild

#99
post #68

Is it just me, or is the Superfish fiasco being covered disproportionately against the other big security story this week, the NSA/GCHQ SIM heist? https://news.ycombinator.com/item?id=9076351

Superfish has more severe practical implications. The SIM heist confirms that few entities have capabilities that almost everyone assumed they have. Superfish enable anyone to attack significant percent of internet users.

Indeed. Most of NSA news are only confirming what everyone could reasonaly already assume - i.e. that yes, they can hit you everywhere. Don't get me wrong, I love NSA stories, but the Superfish one is rightfully more covered because:

- it's an immediate and very serious threat to a lot of people (every script kiddie with room-temperature IQ level can use it to clear someone's bank account)

- it's a very clear example of how customers are literally being fucked over by businesses, and how a big and trusted company turned out to be represented by flat-out lying assholes (one rarely gets to see a case without any room for doubt)

- it's a case that you can (and should) do something about

Re: Windows SSL Interception Gone Wild

#100

Earlier quoted context omitted.

> So why did Superfish not just present itself like a browser plugin They did this for years, actually. They paid add-on developers to bundle their shopping app with the developer's app. I remember this going on ~2010/2011 at least. People were not happy about it to say the least.

And VCs gave them money for this shit. What a fucked up investor world this is. https://www.crunchbase.com/organization/superfish

Here they are:

https://www.crunchbase.com/organization/superfish/investors

I'd love to see people put money where their mouth is and refuse to be funded by those investors... but I'm pretty sure it's not going to happen.

Post reply on HN