2 ms·
An antivirus software that can monitor HTTPS connections should be a non-issue. Because you're already trusting Avast with full privileges, it can monitor every
by 0942v8653 11y ago
An antivirus software that can monitor HTTPS connections should be a non-issue. Because you're already trusting Avast with full privileges, it can monitor every keystroke and screenshot every response from the browser, or read RAM during decryption, or replace your browser with a fake version that captures data, or any number of things. And it can upload it to some remote server if it wants to. It would be incredibly easy to get your bank password without this MITM: just start keylogging when an outgoing connection to example.com is established, wait for an email[TAB], and capture/upload all keystrokes until ENTER is pressed.
The only real problem here is not checking the validity certs. (Which is an incredibly serious problem.)
- venomsnake 11y ago> The only real problem here is not checking the validity certs. (Which is an incredibly serious problem.) There are other problems. I am not sure where the third party doctrine will stand, but you are trusting all of your secure connections to a third party with full consent. If avast get subpoenaed and their software has called home, which any antivirus does - they must collect new samples all the time - this could spell trouble.
- fidget 11y agoIt wouldn't be particuarly hard for avast to operate this system without having the key for the CA leaving your machine.
- muteh 11y agoIt might not be hard for them to do it, but how is the end user meant to know to ask if they do?
- venomsnake 11y agoThat won't help when they send part of the plaintext home. Which any antivirus program does from time to time