Live data from Hacker News

Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

bug1134506.bugzilla.mozilla.org

1–10 of 188 posts

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#2
Bullet point 4 is what I'd been wondering about:

• The Superfish proxy accepts its own certificate, so now that the private key has been leaked, an attacker can mimic an arbitrary site in Chrome and IE

I thought there might be a chance that despite all the other idiocy here, they might have refused external certificates from their own CA, mitigating the risks somewhat. But no suck luck for Lenovo customers!

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#3
post #2

Bullet point 4 is what I'd been wondering about: • The Superfish proxy accepts its own certificate, so now that the private key has been leaked, an attacker can mimic an arbitrary site in Chrome and IE I thought there might be a chance that despite all the other idiocy here, they might have refused external certificates from their own CA, mitigating the risks somewhat. But no suck luck for Lenovo customers!

And this matters because even if you uninstall the program, it leaves the certificate behind, right? So you have to manually remove the cert to shield yourself against future attacks, in addition to removing the program

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#5
post #2

Bullet point 4 is what I'd been wondering about: • The Superfish proxy accepts its own certificate, so now that the private key has been leaked, an attacker can mimic an arbitrary site in Chrome and IE I thought there might be a chance that despite all the other idiocy here, they might have refused external certificates from their own CA, mitigating the risks somewhat. But no suck luck for Lenovo customers!

That would have been comical, considering uninstalling doesn't remove the root cert, so a user would have been more secure with superfish installed than uninstalled.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#6
post #2

Bullet point 4 is what I'd been wondering about: • The Superfish proxy accepts its own certificate, so now that the private key has been leaked, an attacker can mimic an arbitrary site in Chrome and IE I thought there might be a chance that despite all the other idiocy here, they might have refused external certificates from their own CA, mitigating the risks somewhat. But no suck luck for Lenovo customers!

The Superfish proxy accepts any certificate. If you're being MITMed (before Superfish MITMs you), Superfish will help them by replacing their certificate with Superfish's.

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#7
post #2

Bullet point 4 is what I'd been wondering about: • The Superfish proxy accepts its own certificate, so now that the private key has been leaked, an attacker can mimic an arbitrary site in Chrome and IE I thought there might be a chance that despite all the other idiocy here, they might have refused external certificates from their own CA, mitigating the risks somewhat. But no suck luck for Lenovo customers!

And this matters because even if you uninstall the program, it leaves the certificate behind, right? So you have to manually remove the cert to shield yourself against future attacks, in addition to removing the program

Not that this excuses Lenovo in any regard whatsoever, the removal instructions[1] Lenovo link to in their press release[2][3] includes the removal of a certificate.

[1] http://support.lenovo.com/us/en/product_security/superfish_u...

[2] http://news.lenovo.com/article_display.cfm?article_id=1929

[3] http://support.lenovo.com/us/en/product_security/superfish

Re: Browser Vulnerability to Superfish: A Fact-Finding Trip to Best Buy [pdf]

#8
post #2

Bullet point 4 is what I'd been wondering about: • The Superfish proxy accepts its own certificate, so now that the private key has been leaked, an attacker can mimic an arbitrary site in Chrome and IE I thought there might be a chance that despite all the other idiocy here, they might have refused external certificates from their own CA, mitigating the risks somewhat. But no suck luck for Lenovo customers!

The Superfish proxy accepts any certificate. If you're being MITMed (before Superfish MITMs you), Superfish will help them by replacing their certificate with Superfish's.

I don't believe that's true, but if so – for example if it replaces self-signed certs, or certs from any untrusted CA, with its own (force-trusted) cert – then that would be worthy of another scary explicit bullet point.

(It might just accept all CAs locally-configured, and it's accepting its own because they didn't special-case a rejection.)

Post reply on HN