Live data from Hacker News

Is PrivDog another Superfish

news.ycombinator.com

1–10 of 16 posts

Is PrivDog another Superfish

#1
While reading about Superfish, I ran this simple test at https://filippo.io/Badfish/ by visiting the webpage and noticed despite the fact i don't have superfish installed i failed the test and got “Yes, Your connections can be tampered with”.

After quick check on my system, I realized I might have failed the test due to the presence of PrivDog (http://www.privdog.com/) on my system.

Here is a screenshot of Bank of America http://i.imgur.com/pbEFW5X.png

Is this another Superfish?

Re: Is PrivDog another Superfish

#4
Yes, it is!

The fact that you're getting this result from the Badfish test page means that Privdog is not validating SSL certificates correctly. This is incredibly bad -- uninstall this software immediately.

Re: Is PrivDog another Superfish

#5
Looks like one of those malwares that takes the ads out of a website and replaces them with its own. In order to do this over SSL/TLS it has to use its own certificate—as if that weren't bad enough, you're vulnerable to man-in-the-middle attacks through HTTPS.

Re: Is PrivDog another Superfish

#6
post #4

Yes, it is! The fact that you're getting this result from the Badfish test page means that Privdog is not validating SSL certificates correctly . This is incredibly bad -- uninstall this software immediately.

Its bad enough because this was bundled with Comodo Internet Security ( https://help.comodo.com/topic-72-1-451-6840-.html and https://help.comodo.com/topic-169-1-413-6109-.html )

Re: Is PrivDog another Superfish

#7

Looks like one of those malwares that takes the ads out of a website and replaces them with its own. In order to do this over SSL/TLS it has to use its own certificate—as if that weren't bad enough, you're vulnerable to man-in-the-middle attacks through HTTPS.

Why would comodo promote such a software ???

Re: Is PrivDog another Superfish

#8
Actually it is worse than Superfish.

It does TLS MitM, but it doesn't do any verification at all. It just accepts every self-signed cert and replaces it with a cert signed by it's locally installed root cert.

So it completely disables HTTPS protection. Everyone who has this: get rid of it, this is super-dangerous.

Re: Is PrivDog another Superfish

#9
post #7

Looks like one of those malwares that takes the ads out of a website and replaces them with its own. In order to do this over SSL/TLS it has to use its own certificate—as if that weren't bad enough, you're vulnerable to man-in-the-middle attacks through HTTPS.

Why would comodo promote such a software ???

Apparently security software giants have motives other than security these days.

This really makes me put more faith into microsofts own defender.

Re: Is PrivDog another Superfish

#10
post #6
post #4

Yes, it is! The fact that you're getting this result from the Badfish test page means that Privdog is not validating SSL certificates correctly . This is incredibly bad -- uninstall this software immediately.

Its bad enough because this was bundled with Comodo Internet Security ( https://help.comodo.com/topic-72-1-451-6840-.html and https://help.comodo.com/topic-169-1-413-6109-.html )

Neither of those links imply that PrivDog is bundled with those apps. It just mentions it as something you can download.

Edit : Just re-read the linked document. Yes, it does indicate that it's an install-time option. However, I've yet to see confirmation that Comodo software comes bundled with the SSL-intercepting version of PrivDog.

Post reply on HN