2 ms·
> Do vendors normally perform a full security audit of programs they include? Is there an expectation that they would give closer scrutiny to smaller outfits vs
by cplease 12y ago
> Do vendors normally perform a full security audit of programs they include? Is there an expectation that they would give closer scrutiny to smaller outfits vs. top tier software vendors?
OEMs absolutely should own up to responsibility for the crapware they load on their boxes. Saying "it wasn't built in-house" makes about as much sense as an automaker washing its hands of the airbags or other critical parts in the cars they build.
As for how deep of an audit, Komodia's own description of their product should have raised massive alarm bells. Anytime I see websites rewritten without my permission I get incredibly spooked, and that's when it's just HTTP over a network. Intercepting SSL/TLS is just not something any OEM should ever contemplate loading on a consumer machine. It's willful recklessness and engineering malpractice of the worst kind.