Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
bug1134506.bugzilla.mozilla.org
Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
1–10 of 188 posts
Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#2• The Superfish proxy accepts its own certificate, so now that the private key has been leaked, an attacker can mimic an arbitrary site in Chrome and IE
I thought there might be a chance that despite all the other idiocy here, they might have refused external certificates from their own CA, mitigating the risks somewhat. But no suck luck for Lenovo customers!
Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#3Bullet point 4 is what I'd been wondering about: • The Superfish proxy accepts its own certificate, so now that the private key has been leaked, an attacker can mimic an arbitrary site in Chrome and IE I thought there might be a chance that despite all the other idiocy here, they might have refused external certificates from their own CA, mitigating the risks somewhat. But no suck luck for Lenovo customers!
Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#4Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#5Bullet point 4 is what I'd been wondering about: • The Superfish proxy accepts its own certificate, so now that the private key has been leaked, an attacker can mimic an arbitrary site in Chrome and IE I thought there might be a chance that despite all the other idiocy here, they might have refused external certificates from their own CA, mitigating the risks somewhat. But no suck luck for Lenovo customers!
Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#6Bullet point 4 is what I'd been wondering about: • The Superfish proxy accepts its own certificate, so now that the private key has been leaked, an attacker can mimic an arbitrary site in Chrome and IE I thought there might be a chance that despite all the other idiocy here, they might have refused external certificates from their own CA, mitigating the risks somewhat. But no suck luck for Lenovo customers!
Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#7Bullet point 4 is what I'd been wondering about: • The Superfish proxy accepts its own certificate, so now that the private key has been leaked, an attacker can mimic an arbitrary site in Chrome and IE I thought there might be a chance that despite all the other idiocy here, they might have refused external certificates from their own CA, mitigating the risks somewhat. But no suck luck for Lenovo customers!
And this matters because even if you uninstall the program, it leaves the certificate behind, right? So you have to manually remove the cert to shield yourself against future attacks, in addition to removing the program
[1] http://support.lenovo.com/us/en/product_security/superfish_u...
[2] http://news.lenovo.com/article_display.cfm?article_id=1929
[3] http://support.lenovo.com/us/en/product_security/superfish
Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]
#8Bullet point 4 is what I'd been wondering about: • The Superfish proxy accepts its own certificate, so now that the private key has been leaked, an attacker can mimic an arbitrary site in Chrome and IE I thought there might be a chance that despite all the other idiocy here, they might have refused external certificates from their own CA, mitigating the risks somewhat. But no suck luck for Lenovo customers!
The Superfish proxy accepts any certificate. If you're being MITMed (before Superfish MITMs you), Superfish will help them by replacing their certificate with Superfish's.
(It might just accept all CAs locally-configured, and it's accepting its own because they didn't special-case a rejection.)