15 ms·
Savitech USB audio drivers install a new root CA certificate
- brian-armstrong 9y agoSo this is a CFAA violation, right? When will we finally hold someone accountable for blatant security issues like this?
- warent 9y agoHas a government organization used Savitech audio drivers? If not, then there will be no charges
- da_chicken 9y agoIf so, there will be a long drawn out investigation at taxpayer expense which results in a fine which is both a) too small to impact the revenue of the company, and b) immediately waived on the condition that they stop doing what they already can't do by law.
- somebodynew 9y agoIn this specific case (installing a root certificate) I would say it's not actually a CFAA violation because they're not "obtaining information", "defrauding", or "intentionally causing damage". You might be able to argue that installing the driver on a "government computer" produces a violation of 18 USC 1030 (a) (3), but the rules for a mere "protected computer" which covers most internet-connected personal computers are actually not strict enough to cover this. https://www.law.cornell.edu/uscode/text/18/1030 https://www.law.cornell.edu/uscode/text/18/1030
- nkw 9y ago"Whoever [...] knowingly causes the transmission of a program, information, code, or command, and as a result of such conduct, intentionally causes damage without authorization, to a protected computer [...] shall be punished as provided in subsection (c) of this section." "[T]he term 'protected computer' means a computer [...] which is used in or affecting interstate or foreign commerce or communication, including a computer located outside the United States that is used in a manner that affects interstate or foreign commerce or communication of the United States" "[T]he term 'damage' means any impairment to the integrity or availability of data, a program, a system, or information"
- justinjlynn 9y agoLaw is a different language. While it may read like computer code; it isn't. Well, it is but it's as if "goto" and ";" had different meanings depending not only on the last keyword used, but also on the mood of the computer. I wish a straightforward reading was possible but it's often not.
- nkw 9y agoSome parts of the law are easier to appreciate if one considers vagueness and ambiguity can be features instead of bugs.
- rocqua 9y agoThose exact ambiguous laws are the ones that are abused most easily. There is a hard balance between being general enough to cover bad things, without being so general as to allow authorities to prosecute anyone on some charge.
- somebodynew 9y agoThat charge would depend entirely on whether or not installing a root certificate can be considered "intentional" "impairment to integrity". I can't find any case law that would provide the interpretation for this, but I think it's safe to say you probably won't be able to overcome the burden of proving that they caused the damage intentionally if it even qualifies as damage (which I find unlikely).
- swiley 9y agoI'm pretty sure most users actually want the driver installed. The correct solution would be for microsoft to allow unsigned drivers (perhaps with a warning.)
- xstartup 9y agoAlright, so if we get tons of install of our root CA cert. Can we start a new CA?
- toast0 9y agoYes, but CAs can charge money based on (more or less) number of CA root cert installations on the target devices for a company. Some of your competitors have had their current root certs in device preinstalled for a lot longer than you. Entrust and GlobalSign have 2048 bit roots with Not Before before 2000. If I'm going to go with a Johnny come lately root, I may as well use LetsEncrypt because it doesn't cost money. Also, audio drivers may get you desktop share, but getting into the platform store on mobile is a lot harder.
- tialaramex 9y agoThe major trust stores partition their trust of a root by purpose. So Microsoft's trust of a particular root for signing certs that are used in driver code signing is separate from not only Apple's trust of same but also Microsoft's trust of that root for signing TLS certificates. Let's Encrypt doesn't ask for any "trust bits" besides the Web PKI, ie TLS certificates and that's completely deliberate. Purposes other than TLS server and /maybe/ S/MIME are not subject to any meaningful public oversight, you are entirely trusting Microsoft. Which for drivers, or Xbox games is probably fine but it's worth keeping in the back of your mind.
- gruez 9y agothat's a great way to get OS vendors to blacklist your cert and mark your installers as malware
- drzaiusapelord 9y ago>Microsoft provides guidance on deleting and managing certificates in the Windows certificate store Microsoft should mark these as malicious and quarantine them using their built-in AV. If the end user needs them he can remove them from quarantine. Posting advisories no end user will ever see isn't helping much.
- ArchReaper 9y agoWhy are they allowed to bundle malware in their drivers? Why is this not illegal?
- kevindqc 9y agoA CA certificate by itself is not malware? Am I missing something?
- steeleduncan 9y agomalware is certainly a strong term, and generally the definition seems to include computer code, which would exclude installing a certificate. However, once you have installed your own root CA certificate on a computer means you can read all HTTPS traffic originating from that computer, and fake responses. Likely, thanks to having installed that certificate you can read someone's emails, move money out their bank account, and view any files they have stored online. The effect of installing a certificate is broadly similar to the effect of installing a keylogger, and in neither case have you been given a right to do so. In both cases you have altered someone's computer in such a way that you are able to read their encrypted communications, which is certainly in the spirit of what malware means to me. I'm sure that the intent in this case was not malicious, but we would not accept software installing a keylogger because they wish to measure your typing speed, and we should not accept this.
- ArchReaper 9y ago>I'm sure that the intent in this case was not malicious What other explanation is there? Is there a valid reason for an audio driver to silently install a CA cert?
- tialaramex 9y agoAs described above, some versions of Windows require drivers to be signed proving who made them. For this to work Windows needs a list of CAs trusted to issue the certificates. Whether "I am not paying somebody £100 for a cert" constitutes a valid reason is arguable. But that seems to have been their plan here.
- ryan-c 9y agoThe "Universal ADB Driver" for Android devices[1] also installs a root CA, however it instead generates the CA during install, signs the driver, deletes the private key, then installs the CA and driver. 1. https://github.com/koush/UniversalAdbDriver https://github.com/koush/UniversalAdbDriver
- hamandcheese 9y agoWhat good is a root CA with no key?
- xgbi 9y agoIt is actually clever: - generate a fake CA and use it to sign your driver on the fly; - add the generated root CA to the trusted list - delete the private key so that nobody else can sign anything with this CA - now windows will happily consider this driver as worthy of trust and install it.
- TylerE 9y agoThat sounds very un-clever (edit: I mean by Microsoft). Why couldn't malware do the exact same thing?
- slededit 9y agoPresumably you need to grant the installer admin privileges for it to work
- weddpros 9y agoJust imagine what the developer thought when his boss said "we don't want to buy an actual certificate, find something that works". And now this developer is learning on HN he should remove that line in his resumé. Or maybe he thought it was a clever idea... Let's call it a learning experience.
- voltagex_ 9y ago
- grandalf 9y agoIs there software that will check the certs on my computers to make sure no software has done this?
- revelation 9y agoWell you can look at the certificate store by running certmgr.msc, but it's a dangerous game - do you trust Go Daddy, COMODO or Symantec any more than you do Savitech? They have all at one point or another given reason to not even entrust them with organising a piss-up in a brewery. Other applications like Firefox have their own independent root CA store.
- tialaramex 9y agoMmm. I think the brewery test is an unfair comparison. Our problem is not that the major CAs are hopeless. If they were hopeless we'd have abandoned PKIX years ago. Instead the problem is that they're good but not as good as we'd like. We are looking for somebody who can run aforesaid event fifty times a year for the general public without anybody falling in any of the machinery. In hindsight drunk people in an industrial workplace was a mistake, and so we can and should demand they do their best to make it safe, but perfection just isn't to be expected.
- adzm 9y agorcc for Windows does this, but the official site appears to have been suspended. I'm surprised how difficult it has been finding other ones.
- currysausage 9y agohttps://www.trustprobe.com/fs1/apps.html https://www.trustprobe.com/fs1/apps.html and http://hexatomium.github.io/ http://hexatomium.github.io/ are still online, but the last RCC version is from September.
- Osiris 9y agoWhy does Windows allow programs to install root CA certs without separate user intervention (beyond the initial "grant admin permissions" dialog)?
- 1_2__4 9y ago..because admin permissions are just that? Once you've granted superuser that's kind of the end of any further effective gates.
- throwaway130917 9y agoMaybe it's time for desktop operating systems to adopt permissions systems like smartphones. Permission for network access, permission for non-current user files and registry, permission to install certs.
- kpil 9y agoYes, why not? Unfortunately all "secure" or "trusted" computing efforts seems to be focused on depriving the owner of permissions and command over the computer, and instead transfer that to large copyright holders. But I suppose the Android security model would make sense, which seems to be based on a traditional unix security model combined with that each program will run as a separate user and having it's own set of group memberships. As long as I don't need to install a rootkit on my own computer.
- skybrian 9y agoAnd how would they do that? There is the Mac App Store and Windows Store, but most apps are still installed without using them due to their restrictions.
- leggomylibro 9y agoSystem call returns an error code if you lack permission. The default handler could be to ask, but if the user says no then the application has to handle the error or crash.
- 9y ago
- revelation 9y agoThe only version of Windows XP that enforces driver signing is the unicorn 64 bit one, surely they didn't develop the driver for that? And what kind of odds do I get on the certs having a EKU for anything but driver signing?
- fiatjaf 9y agoThis, and all other thousands of cases of malware in the universe should mean something for those who defend "native" apps over webapps.
- walrus01 9y agoI would honestly be more worried about the root CAs which are enabled by default in the most popular OSes and browsers, with root CA privileges for government of China controlled entities, Turkish government entities and unethical/shoddy root CAs such as Symantec. The Netherlands recently passed a law allowing the government specifically to use false keys and run MITM on crypto, which brings into question all .NL based CAs.
- rvanmil 9y agoDo you have a reference to this law in The Netherlands?
- PhantomGremlin 9y agoPosted to HN a few days ago. Didn't get a lot of discussion. https://news.ycombinator.com/item?id=15595928 https://news.ycombinator.com/item?id=15595928
- rocqua 9y agoThere is an upcomming advisory (i.e. non-binding) referendum about this law coming up. Specifically, the referendum is about reversing the law. Notably, some parties in the newly minted government have declared their intention to ignore the referendum. They back this by two arguments "It is needed for security" and "We are going to remove the advisory referendum anyway, so we get to ignore this one". That second point is kind of interesting, because the referendum is possible due to a rather new law. We had one before that went rather poorly, so now we want to get rid of it. The actual law is here [1] this site [2] advocates for the referendum. I'm afraid I don't know of any english sources. Quoting from the law, and applying my own translation >> Article 45. Member 1 The services are authorized to: a. (Basically, do exploratory searches of networks) b. Use false signals, false keys, false identity or intervention by third parties to gain acces to automated systems. This can be done with the help of technical tooling. Article 45. Member 2 The authorization from member 1b above also authorizes: a. The defeating of any security measures b. Installing technical measures to reverse encryption on data stored or processed by automated systems. c. (references article 40) d. To copy data stored or processed by an automated system. Article 45 Member 2 (summarized, the government needs to give written permission for any of the above to happen) >> This seems to be the referenced passage based on a preliminary search. [1] https://zoek.officielebekendmakingen.nl/kst-34588-A.html https://zoek.officielebekendmakingen.nl/kst-34588-A.html [2]https://sleepwet.nl/ https://sleepwet.nl/
- arca_vorago 9y agoOne more reason to add to the innumerable list of why not to use windows.
- djsumdog 9y agoA bad actor could just as easily post a script as "Show HN" with some cool stuff in it that you install via: curl https://example.com/some_script.sh | bash A lot of people don't check those. Use the non-OSS nvidia or ATI drivers? You have binary blobs (don't for ATI btw, the OSS ones are 10x better). Use bluetooh/Wi-Fi on Linux, congratulations you are using closed binary blobs. I still love Linux, but I don't hate windows. We're not in the 90s. Bill Gates isn't master of the Borg.
- arca_vorago 9y agoI think you underestimate the insidiousness of such systems, and your response is completely logically fallacious, and doesn't support your conclusion whatsoever. So if I installed a random script via curl (I prefer wget) and because there are still some proprietary hardware that needs closed source binary blobs... That suddenly means GNU/Linux and windows are on the same footing? No, not at all, and I'm tired of hearing that trite and clichéd response. The four freedoms matter. No, its not the 90s. Now its worse!
- joosters 9y agoIt seems unacceptable to me that the updated drivers do not automatically uninstall the CA. How is an ordinary user meant to navigate the certificate store and delete the CA?
- pfarnsworth 9y agoIs there a list of trusted CA certs that we could use to scan to see if we have any that may not be trusted?
- herf 9y agoYou can use sigcheck -tv (sysinternals) to test against Microsoft's list. I prefer RCC (root certificate checker) and have used it in the past, but the website seems to be suspended.
- elbigbad 9y agoCan someone explain root certificates to me and why this is an issue? I know they sign certificates with a private key at a high level, but don't get the implications of that generally.
- arkadiyt 9y agoAnyone who installed this audio driver could have all their https traffic intercepted by Savitech.
- elbigbad 9y agoDoes this mean savitech needs to hypothetically set up some mitm attack somewhere and wait for you to send traffic, then they can decrypt and read, or does it mean that they can do that direct from your computer by virtue of that root certificate?
- xythobuz 9y agoThey would need to MITM you somewhere, but that could probably happen in their audio driver that's already installed and running on the target machine.
- deleted 9y ago[deleted]
- jchavannes 9y agoThey would need to MITM you. But take into account that it doesn't need to be Savitech. If Savitech was compromised, an attacker could get access to their private key. In a sense, your security becomes dependent on the security of Savitech. I imagine their private key is not as securely stored as a real CA would store theirs. (e.g. with Superfish, Lenovo included the private key on all laptops, for anyone to grab[1]) [1] https://en.wikipedia.org/wiki/Superfish#Lenovo_security_incident https://en.wikipedia.org/wiki/Superfish#Lenovo_security_inci...
- 9y ago
- userbinator 9y agoI am not saddened by this event, but by the fact that such occurrences will only add momentum to the movement to lock down computing devices and take freedom away from their users: https://news.ycombinator.com/item?id=12061320 https://news.ycombinator.com/item?id=12061320 Those worrying about security should remember that device drivers already run in ring 0 and can do anything they damn well please. Thus I say: Good on Savitech for not being afraid to rebel against; and fuckings to the corporatocracy that is certificate authorities and the authoritarian security industry.
- chubs 9y agoI hold out hope for new microkernel OS's like Redox where drivers live in userland to solve this kind of thing.
- TeMPOraL 9y agoI do not know what to do anymore. I am with you here, as I've been for many years (you link to a comment of yours that links to a comment of mine, for that effect). I'm even fond of saying, "security vs. fun - pick one". But I start to increasingly understand the arguments from the other side. Consider: what I consider an essential "fun" of computing is being able to alter software running on my machine as I see fit. If I want to make it so that Windows Notepad is pink, or supports Emacs shortcuts, I should be able to mess with both binary on my hard drive and running process in memory, because it's my computer and my rules. But the same mechanisms allow an evil person to make my mother's Notepad look like her e-mail account login screen and exfiltrate data from that. I dream of having an OS as malleable and tightly integrated as Lisp Machines were, but I wouldn't dare connect it to the Internet these days. So what can one do? How to approach it? Is there even a way to create a computer that both respects the end-user as its rightful owner and can be safely used to conduct business and pleasure on-line? I honestly don't know if this is even possible in principle. If it is, I would appreciate being pointed towards possible solutions, because this - I believe - is a case worth fighting for.
- iaml 9y agoA hardware switch would do nicely.
- edejong 9y agoPhrased differently: operating system Microsoft Windows allows silent installation of Root Certificate during installation of unrelated USB driver installation, despite featuring a micro-kernel design.
- obituary_latte 9y agoCurious as to why EMC got notified 20 days before anyone else...