3 ms·
(The article is almost a year old, but the issues remain) The AV MITM certs are not exactly Dell- or Lenovo-bad, as they are all uniquely generated in each ins
by wmt 11y ago
(The article is almost a year old, but the issues remain)
The AV MITM certs are not exactly Dell- or Lenovo-bad, as they are all uniquely generated in each installation, so you can only fake traffic on computers you have Admin access - and then you don't need Avast for that.
However, the real issue is if these MITM-proxies render compromised, expired or otherwise insecure TLS-connections "secure".
The bare minimum should be to respect the cert storage of the computer, although that will fail with any application with its own storage, like Firefox. To me this feels like it has too many points of failure to increase security instead of lowering it, so you really would focus on detecting malicious content based on other things, like the host reputation, files that land on disk, or maybe having a browser plugin that would see at least some of the decrypted HTTPS content.