11 ms·
Windows SSL Interception Gone Wild
- nugget 12y agoJust to be clear, Facebook and Google hate any software that allows users to modify content within their walled gardens (whether that's an adblock, ad injector, or other). These companies want a totally controllable user experience in order to maximize their own user metrics and monetization. My fear is that these companies will use this Superfish debacle to attack and restrict the ability for users to download legitimate software which leverages these technologies. As users and developers, we want to retain this ability. Adware sucks, and there are dozens of anti-virus companies who should be all over anyone who tries to pull this crap. The problem here is not with MITM, SSL packet inspection or modification. The problem here is that Lenovo allowed themselves to be turned into a distribution channel for a poorly implemented, spammy piece of adware for a few extra pennies.
- mentat 12y agoI'm not sure why a normal user would ever need to add CAs to their root store. Can you clarify?
- RDeckard 12y agoRealizing an adblock mechanism, for one. (Similar to InterMute in late 90s, and admucher.com now.)
- deleted 12y ago[deleted]
- duskwuff 12y agoThat's a really intrusive, dangerous way of implementing ad blocking, though. Much better to have that functionality live in the browser itself (or an extension).
- hamburglar 12y agoDepends on what you mean by "normal user." It's somewhat advanced, for sure, but many companies use private CAs to issue certs for their intranet sites, and the ability to install those certs on client machines is very useful.
- jonah 12y agoPlenty of enterprise users need to. There are other reasons too. I presume 'nugget is talking about the HTML rewriting aspect of the software. Injecting additional/unwanted tracking code == bad, user-requested re-writing of content == good.
- dingaling 12y agoOddly Google's Android team took a different approach; on Android 4.0+ there is no way to install additional certificates without a periodic "Network may be monitored by unknown third party" notification being presented. Very annoying if you wish to use your own CA or add another and it is also dangerous in that it masks any cert installation by malware.
- dredmorbius 12y agoAdding (or removing) CAs is a fully legitimate activity. Your own site, work, or vendor / client sites could be added. Or you could want to remove a Comodo (or Honest Achmed's Used Cars and Certificates). http://www.livehacking.com/2011/04/25/honest-achmeds-used-cars-and-certificates-wants-to-become-a-trusted-certificate-authority/ http://www.livehacking.com/2011/04/25/honest-achmeds-used-ca... https://bugzilla.mozilla.org/show_bug.cgi?id=647959 https://bugzilla.mozilla.org/show_bug.cgi?id=647959 Just because your OS / browser vendor "trusts" a cert doesn't mean you should.
- userbinator 12y agoJust because your OS / browser vendor "trusts" a cert doesn't mean you should. In other words, users should always have the right to control who they (indirectly) trust. That's what the comment above is referring to - it will be even worse if Superfish is used as an excuse to take away this right.
- dredmorbius 12y agoQuite right.
- Buge 12y agoI add CAs to my root store so that I can view my https traffic using fiddler. Also if you want to use http://www.cacert.org/ http://www.cacert.org/ you need to add their cert.
- madeofpalk 12y agoTo be fair, I'm sure any website owner would want to prevent others from modifying their own website and how users view/interact with it.
- userbinator 12y agoFor the ones who are pro-DRM, that is probably true; the ones who realise that trying to do that is as futile as forcing one to sit in front of the TV during the adverts, probably not. Userscripts and userstyles are very popular, and I see no particularly large backlash against them.
- kbenson 12y agoIt's not as simple as that though. It's perfectly acceptable to want to have control over how your site is presented while still allowing your data to be accessible. If I spent a lot of time on my site UI, I wouldn't want some third party tweaking it, when that may mean I make changes to my front-end and some percentage of users break which I have no real control over. This remains true whether I replicate every capability in an open REST interface or not.
- deleted 12y ago[deleted]
- bsdetector 12y ago> My fear is that these companies will use this Superfish debacle to attack and restrict the ability for users to download legitimate software which leverages these technologies. They already have, with HTTP/2. Encryption is mandated for HTTP/2 so something like Privoxy (or even just a caching proxy) has to use a Superfish-like method to bypass the encryption. The only alternative is to modify the browser, which they are also locking down with unchangeable ChromeOS and limiting plugins to only officially sanctioned ones. ...and you won't really even be able to just not use HTTP/2 because the web will be much slower as pipelining is not even implemented in Chrome, and Firefox will no doubt drop it soon. Websites optimized for HTTP/2 could take minutes to load without pipelining. The real irony is that neither Google nor Mozilla determined what software caused pipelining problems, so guess what, it was Superfish and its like. Instead they made a new protocol that requires Superfish-like MITM interception, to work around problems caused by Superfish-like MITM malware.
- gsnedders 12y agoHTTP/2 doesn't actually require TLS (it got removed because of too many people pushing for it not being required for things like home routers and the like), though none of the major browser vendors intend on supporting HTTP/2 without it.
- whytry 12y agoYour going to get hellbanned if you keep talking like that. We love our corporate masters here.
- larvaetron 12y ago> Superfish uses a third party library from a company named Komodia to modify the Windows networking stack This is the second article I've read that states this - Superfish does no such thing.
- jrochkind1 12y agoHow do you know one way or the other? Care to enlighten us?
- iancarroll 12y agoWhat doesn't it do? It is modifying the network stack by intercepting all traffic (presumably through a proxy), right?
- maxerickson 12y agoMy (not very studied) understanding is that it used SSL Digestor: https://web.archive.org/web/20150220003144/http://www.komodia.com/products/komodias-ssl-decoderdigestor https://web.archive.org/web/20150220003144/http://www.komodi... installed as a LSP: http://en.wikipedia.org/wiki/Layered_Service_Provider http://en.wikipedia.org/wiki/Layered_Service_Provider "modify the windows networking stack" is not an absurd description of that.
- quotemstr 12y agoYou may find this Stackoverflow discussion interesting. Note the date. https://stackoverflow.com/questions/16269624/the-truth-behind-dll-injection-with-metro-applications-nektra-vs-komodia https://stackoverflow.com/questions/16269624/the-truth-behin...
- reedloden 12y agoAh, so this is why Facebook tries to load Flash on almost every page... Allows them to gather data like this. Always wondered why Flash was "needed". (another reason to put Flash behind click-to-play and/or push for HTML5 video)
- mkjones 12y agoI suspect flash is generally used to play sounds from chat messages - the https man-in-the-middle detection is heavily sampled, as referenced in https://www.linshunghuang.com/papers/mitm.pdf https://www.linshunghuang.com/papers/mitm.pdf. [I work at FB, but not on sounds or directly on https man-in-the-middle detection.]
- hobarrera 12y agoNope, without flash you still get the chat sound messages. I've no flash on my system and the only thing that's different on facebook is that I can't watch user-uploaded videos. Only their mobile site supports HTML5 last I checked.
- mbel 12y agoIt is still possible that they use flash as default audio source and fallback to HTML audio if flash is unavailable. Although of course it would be better if they could get rid of the flash altogether.
- eli 12y agoI don't follow why this upsets you. Seems like an argument for why allowing flash to run can be used for good?
- timothya 12y agoSide note: click-to-play is a usability feature, not a security feature. It's still possible for Flash code to run before the user "clicks to play".
- 12y ago
- nissehulth 12y ago"We've observed more than a dozen other software applications using the Komodia library" is the scary part.
- whytry 12y agoHow about MS's continued use of winsock?
- deleted 12y ago[deleted]
- Intermernet 12y agoPlease elaborate? What about it? (Seriously, I'd like to know what the current perceived issues with winsock are, I'm a bit out of date with Windows security)
- chinathrow 12y agoThis. The install base is reportedly up to 40m users. https://twitter.com/ow/status/568935755344580608 https://twitter.com/ow/status/568935755344580608 Superfish: Go shame yourself. If I was an investor in your company, I'd pull my money now.
- deleted 12y ago[deleted]
- ams6110 12y agowe see several reasons to be concerned about this practice in the case of Superfish and others. Chief among those is privacy—the Superfish software can see all of the computer user's activity, including banking, email and Facebook traffic. Never mind that Facebook sees all the computer user's Facebook traffic, and cross-indexes it with every other bit of data gleaned from their vast graph and uses it for profit.
- zevyoura 12y agoYes, and they do all that with the user's consent.
- userbinator 12y agoYou had to agree to have Superfish installed too, if Lenovo is to be believed.
- dredmorbius 12y agoUm, really? How informed is that consent? What of sites that unilaterally change rules retroactively? Or fail to provide reasonable alternatives? Facebook does all of the above. To an extent that I don't trust it, and don't use it. But there are plenty of other services which wave the "but you consented!" flag. Google comes to mind, and I've had my set of issues with them as well.
- ptaipale 12y agoUmm, if you're using Facebook, it should be fairly obvious that you are giving your information to Facebook. Yes, I call that an informed consent.
- Ded7xSEoPKYNsDd 12y agoAnd when you're browsing a web site with a Facebook Like button (that you don't click on), you're giving information about your browsing habits to Facebook and it's totally non-obvious.
- jgwest 12y agoI think it's interesting that this BADWARE install was found more or less accidentally... apparently by some tech dude noticing that his bank login presented a Silverfish-issued CA cert. Shouldn't the possiblity have been forseen and addressed beforehand? Perhaps by... (1) Anti-virus / anti-malware makers. Does this software not notify the user when strange CA certs are put into a system's root certificate storage? I understand that certain businesses do this for traffic monitoring... so it might be legit... but still, no user notification? (2) Microsoft. Do their license terms really allow OEMs to install MiTM proxies and screw around with the root certs? Microsoft could do a good thing here by disallowing this sort of malfeasance... or is there some problem I'm not seeing with such an action? If this were done in, say, OS X (unrealistic, of course), it would be found out and the whole tech world would know about it in a jiffy. John Siracusa would be howling at the Internet moon within a couple of hours...
- AnthonyMouse 12y ago> (1) Anti-virus / anti-malware makers. Does this software not notify the user when strange CA certs are put into a system's root certificate storage? I understand that certain businesses do this for traffic monitoring... so it might be legit... but still, no user notification? It was installed by the OEM. Doesn't really help if it only notifies the OEM. > (2) Microsoft. Do their license terms really allow OEMs to install MiTM proxies and screw around with the root certs? Microsoft could do a good thing here by disallowing this sort of malfeasance... or is there some problem I'm not seeing with such an action? The general solution to what you're talking about is to prohibit the OEMs from installing anything by default. The problem is the OEMs wouldn't like it and Microsoft has to keep the OEMs happy lest they get any bright ideas about offering their computers with Ubuntu for $50 less than Windows.
- aragot 12y ago... or they could develop badware for Ubuntu.
- scholia 12y agoIt's not just that the OEMs wouldn't like it. The US DoJ sued Microsoft (and tried to break it up) to prevent it from having any control over what they do. In fact, Microsoft doesn't know what OEMs are installing as "Windows" unless it goes out and buys one of their PCs. Otherwise, some OEMs have tried installing versions of Linux, with negative financial results. A few are still trying. The real problems are selling and supporting them.
- ademarre 12y agoIs it just me, or is the Superfish fiasco being covered disproportionately against the other big security story this week, the NSA/GCHQ SIM heist? https://news.ycombinator.com/item?id=9076351 https://news.ycombinator.com/item?id=9076351
- saganus 12y agoMaybe it's not just you, however I think a potential factor to give one more attention is that you can do something about the first, at least in the short term. Besides cleaning your box, you can blame Lenovo, stop buying their products, promote the boycott, etc. All things that regular people can do and serves as an anger/stress/steam release valve. The NSA news, even though it is/should be a much more important or pressing issue, it's something you "can't do anything about". I mean, ostensibly you can do a lot as a citizen, however most of those actions have long term effects and thus are not as useful as a release valve. It involves commitment and even sacrifice, whereas blaming a corporation (however righ you might be) is much more immediate and serves the purpose of having someone to blame for that and lots of other stuff, i.e. you can then blame the general state of IT security, then how the govt does nothing about it, how privay is nowadays non-existent, think of the children, etc. I also believe another factor is the way news have found a way to tap into this need for the audience to have a release valve. Something or someone to be angry at and so all your problems can be channeled to that. Where I live I've seen a growing amount of newspapers and news media that just basically do a certain journalism that does not bring anything to the table but things to be raging about. I guess it's easier to sell stuff when you can easily get people "on your side", and since there's always a lot of people angry at something, it becomes easy to have an audience. So what's the point then (from the POV of the media) of bringing "important" (for different values of important) news to the front page when that would require their audience to commit to actions that would last several years (change your country's politics for example) and thus not as easily enticed to "get on your side" (and thus buy your media), if on the other hand you could bring, I guess you could call them "anger-bait" (like click-bait) news, and have everyone talk about it by virtue of functioning as an escape valve where people relieve their stress, fear, anger, etc? I'm not saying it's a good thing, but I've seen more and more evidence that points in this direction, and I guess that would be my answer as to why one has much more attention than the other. Edit: As an analogy, I read somewhere about the recent Charlie Hebdo (sp?) attack and how it got disproportionate attention vs the two thousand killed by ISIS (I believe it was ISIS... or Borok Haram?). Maybe it's a similar thing. You believe you are able to do "more" when it's close to home (Western nation) vs far (somewhere in Africa, far away from me).
- aosmith 12y agoAnd this is why I run linux...
- scrollaway 12y agoThe superfish issue is why you run linux? You could've given the world a bit of a heads up on it, don't you think?
- aosmith 12y agoNo, if you wipe the hd and reinstall it's not an issue. I run linux because I like it. Stuff like this doesn't happen with mainstream distros.
- shpx 12y agoI guess you haven't heard of amazon+ubuntu? This is just a side effect of maximizing profits, and it happens to anyone making a profit, unless they're idealistic enough.
- icebraining 12y agoUbuntu wasn't MITM your connections, it's hardly the same. They had ads, not a massive security hole.
- mbel 12y agoAlso they informed useres about Amazon integration and afaik provide a way to disable it.
- guelo 12y agoI know at least Mint does DNS and browser plugin ad injection.
- sroerick 12y ago
- logn 12y agoBrowser plugins can read SSL pages no problem. So why did Superfish not just present itself like a browser plugin? Then it's just normal bloatware and probably pulls in the same profit. Some people might uninstall it is the only reason I can think why they didn't go this route. They could have pre-bundled Chrome and FF to avoid having users ok the plugin installation.
- ProAm 12y agoCan browser plugins install root CA certs? Honest question, Im not sure but I would be surprised if they could?
- logn 12y agoYou can write anywhere to disk where user has privileges (at least in FF). Not sure if that's enough. But I don't think you need a CA at all since plugins can see the full DOM (whether SSL or not). Like if you "inspect element", view source, or run firebug. The plugin is already written too: https://addons.mozilla.org/en-US/firefox/addon/windowshopper-automatic-price-/ https://addons.mozilla.org/en-US/firefox/addon/windowshopper...
- chinathrow 12y agoMozilla should just pull this plugin from addons, seriously.
- joshstrange 12y agoWhat am I missing here? What makes this addon so bad? It looks like it injects buttons/overlays to show "lower" prices of items you are already viewing. While I have zero desire to install this addon I'm failing to see what it's doing that makes it deserving of being pulled.
- chinathrow 12y agoThe company is scum, as has been proven the last couple of days. I don't know why anyone (Mozillas Add-On place included) should support them and carry their software.
- robbintt 12y agoHoly shit, I bought a lenovo Z50-70, ripped out my drive, and put in a linux drive. I've never been happier to have some semblance of control over these things.
- romanovcode 12y agoYou do realize.. ..that you can just re-format your drive as it is.
- mschuster91 12y agoOne week ago the HDD firmware manipulation by NSA/GCHQ was revealed. So, if the snoops intercept the parcel with the laptop, it's better when you go into a computer parts store and buy a random HDD...
- deleted 12y ago[deleted]
- robbintt 12y agoI recently bought one of these and didn't even boot it into windows before ripping out the drive and tossing in a linux installation on my SSD. Never been more grateful to be technologically competent. Also, I am wiping that drive.
- SixSigma 12y agoYou're the Chuck Norris of HN
- romanovcode 12y agoToo edgy for me :)
- SixSigma 12y agoCome up with your own comments
- TazeTSchnitzel 12y agoAll those HDDs at the store also have manipulated firmware.
- wslh 12y agoBut this problem is not only about CA certs. If the application sits in the same computer it can intercept the SSL libs used in the application (wininet for IE, and the Firefox and Chrome used libs) to watch and modify SSL connections. This can be done without any proxy or certificate installation.