Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Crippled isn't the word. They broke browser cryptography. The Superfish MitM proxy on the host is validating any cert it gets, even patently bogus ones. As a result it's possible for a networked MitM who is actively going after SSL/TLS traffic to see all traffic with no need to have the Superfish private.

Here's a screenshot of what their MitM proxy provides back to the browser for a compromised connection to Bank of America:

https://defaultstore.com/four.png

Note that my MitM proxy cert is one gen'd with OpenSSL and is not the Superfish private! While it's cool that the private can be extracted, given the failure of the Superfish software to properly validate the public in the SSL/TLS handshake, the Superfish private isn't something a bad guy needs to get in the middle of encrypted traffic.



Once Lenovo was bought by a chinese company... didn't everyone kind of assume the state of China would use this opportunity to do what the NSA does for American hardware? The extent of the NSA's actions weren't known at the time, but you had to assume China would be less bound by restrictions.


Lenovo has always been a Chinese company. I think what you are recalling is that they bought the PC part of IBM (thinkpads and whatnot).


SuperFish is based in Palo Alto and funded by DFJ.


You're shitting me?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: