4 ms·
I thought this vulnerability was due to them installing a root CA so if you have that CA key you can always generate self-signed certificates for all websites o
by dignick 12y ago
I thought this vulnerability was due to them installing a root CA so if you have that CA key you can always generate self-signed certificates for all websites on the fly? A software update wouldn't change that, unless it removed the root CA certificate, but this defeats how superfish works. That was my understanding, I'd be interested to learn how I'm wrong!
- patcheudor 12y agoThere are multiple issues, the fact that it's not properly passing validation state being the worst, IMHO. Filippo Valsorda from CloudFlare has done a write up on it: https://blog.filippo.io/komodia-superfish-ssl-validation-is-broken/ https://blog.filippo.io/komodia-superfish-ssl-validation-is-... I found the flaw early on the 19th and attempted to contact Lenovo and Superfish to disclose. My mail bounced to their security e-mail boxes and I never heard back from anyone at the e-mail addresses that were sucessfull so I then reached out to Komodia directly and have been in communication with them since. They understand the flaw and are working to patch all of their software. I've really been torn on this one. With the private in the wild it's not necessarily irresponsible disclosure at this point to go public, but I wanted to at least give the software vendor a chance, whether the community views them as deserving of that or not before publishing all the details of my own findings.
- dignick 12y agoAh that link explains it, thanks. Very interesting. What a mess!