Live data from Hacker News

Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks

bleepingcomputer.com

1–10 of 123 posts

Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks

#4
post #2

> the software was also installing a root certificate into the Trusted Root CA Certificate store. This kind of stuff shouldn't even be legal.

As a bit of a layman, is there even any legitimate reason at all (other than a user installing it in their own machine for reverse engineering purposes) for anyone to install a root certificate anymore?

I could understand it if it was a small company doing so at the time when certificates were expensive, but Sennheiser has plenty of money and certificates can be obtained for free nowadays.

Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks

#5
post #4
post #2

> the software was also installing a root certificate into the Trusted Root CA Certificate store. This kind of stuff shouldn't even be legal.

As a bit of a layman, is there even any legitimate reason at all (other than a user installing it in their own machine for reverse engineering purposes) for anyone to install a root certificate anymore? I could understand it if it was a small company doing so at the time when certificates were expensive, but Sennheiser has plenty of money and certificates can be obtained for free nowadays.

Corporate MITM proxies, like Forcepoint/Websense. For loose definitions of "legitimate."

Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks

#6
post #4
post #2

> the software was also installing a root certificate into the Trusted Root CA Certificate store. This kind of stuff shouldn't even be legal.

As a bit of a layman, is there even any legitimate reason at all (other than a user installing it in their own machine for reverse engineering purposes) for anyone to install a root certificate anymore? I could understand it if it was a small company doing so at the time when certificates were expensive, but Sennheiser has plenty of money and certificates can be obtained for free nowadays.

It's perfectly normal to install new root certificates - for example, so that a company can sign internal websites (or for MITM proxies).

It's incredibly shady to have random software install into your trust store.

Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks

#7
post #4
post #2

> the software was also installing a root certificate into the Trusted Root CA Certificate store. This kind of stuff shouldn't even be legal.

As a bit of a layman, is there even any legitimate reason at all (other than a user installing it in their own machine for reverse engineering purposes) for anyone to install a root certificate anymore? I could understand it if it was a small company doing so at the time when certificates were expensive, but Sennheiser has plenty of money and certificates can be obtained for free nowadays.

I run some services for my private use. It's crazy that I need to have them certified by some third-party over-seas CA since I can't get my own devices to trust my own certificates.

We're not at that point yet, but running your own trust root is getting quite annoying. For example, Android constantly nags about "network might be monitored" when custom certificates are installed.

Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks

#8
post #7
post #4

Earlier quoted context omitted.

As a bit of a layman, is there even any legitimate reason at all (other than a user installing it in their own machine for reverse engineering purposes) for anyone to install a root certificate anymore? I could understand it if it was a small company doing so at the time when certificates were expensive, but Sennheiser has plenty of money and certificates can be obtained for free nowadays.

I run some services for my private use. It's crazy that I need to have them certified by some third-party over-seas CA since I can't get my own devices to trust my own certificates. We're not at that point yet, but running your own trust root is getting quite annoying. For example, Android constantly nags about "network might be monitored" when custom certificates are installed.

> Android constantly nags about "network might be monitored" when custom certificates are installed.

This is why I baked my home network certificate into the system trust store when building the ROM.

Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks

#9
Have any hardware companies ever written good accompanying software? From all the custom-ui graphics card config nonsense to utilities that phone home of their own accord, to things like this which are laughably awful.

I feel glad I left for the mild shores of Linux in the early 00s.

Re: Sennheiser Headset Software Could Allow Man-In-the-Middle SSL Attacks

#10
post #2

> the software was also installing a root certificate into the Trusted Root CA Certificate store. This kind of stuff shouldn't even be legal.

Why? The user chose to run the installer and opted to give it control to modify their computer. What part of that process should be illegal?
Post reply on HN