3 ms·
The core of the outrage about Superfish is centered on the fact that it is preinstalled, that we are given no choice about its existence. In the case of PrivDog
by john_saxon 12y ago
The core of the outrage about Superfish is centered on the fact that it is preinstalled, that we are given no choice about its existence. In the case of PrivDog, we do have a choice to install it. Shady software will always exist, it's just that in the Superfish case it was shoved down our throats without our knowledge.
- shangxiao 12y agoYeah but you don't expect shady software from a company that's supposed to be protecting us.
- mkozlows 12y agoThe core of the outrage about Privdog is that it's created by the founder of Comodo, and distributed with Comodo products, and therefore Comodo doesn't really seem like a company you should trust, but you don't have a choice, because they're a trusted root CA.
- john_saxon 12y agoWhich therefore calls for a deep, deep look at who we do trust and who we should trust.
- TazeTSchnitzel 12y agoWell, they are a company you'd trust, given they're a CA. If I saw something made by Comodo, before today, I'd probably assume it was safe...
- userbinator 12y agoThe question is, do you trust Comodo's Privdog ad-networks more or less than all the others out there? If you are already trusting Comodo as a CA, wouldn't you think that Privdog's ad networks have been through some sort of approval process by Comodo and therefore, more trustworthy somehow? Thus, wouldn't it be better if those were the only ads you saw? That seems to be their sales pitch. The implementation lacking any cert verification is a total fail (it might not be intentional at all), and I personally trust http://localhost:8080/blocked.gif http://localhost:8080/blocked.gif more than any ad network... but I can see the reasoning behind the product.
- seestheday 12y agoI'd argue that this is also stealing from the content creators or other people/companies that added actual value (e.g. group running a forum that pays for hosting with ads).
- tomjen3 12y agoCan't we just remove their root certificate from the trust stores then?