Showing posts with label Komodia. Show all posts
Showing posts with label Komodia. Show all posts

Sunday, 1 March 2015

EFF: Install New Computer Ever Again

EFF

If you buy a new computer that must first install all over again, because the software that comes standard is not to be trusted. That secures the American civil rights movement EFF. Following are programs like Superfish and PrivDog who intercepted the SSL traffic of users to inject ads and thus users exposed themselves to all kinds of risks.

This week it was announced that next Superfish, standard on some Lenovo notebooks shipped, other programs intercepting SSL traffic. One of these programs was PrivDog . A vulnerability in certain versions of PrivDog caused the software each certificate which replaced the Internet came and intercepted by a self-signed certificate. Even though it was about certificates that were not valid in the first place.

The Decentralized SSL Observatory of the EFF, which gathers information from the HTTPS Everywhere plugin for Firefox, has collected more than 17,000 different certificates PrivDog users. "Each of these licenses may be an attack. Unfortunately there is no way to know this for sure" says Joseph Bonneau of the Electronic Frontier Foundation (EFF).

"So what have we learned from this Lenovo / Superfish / Komodia / PrivDog debacle? For users, we have learned that the software is pre-installed on your computer can not be trusted, which means that reinstalling a clean operating system standard now procedure must be if someone has bought a new computer, " said Bonneau. The main lesson, he says, for software companies, which must stop intercepting SSL traffic of their users.

Monday, 23 February 2015

Weak "Superfish Certificate" Found In More Software


It is not just the owners of a Lenovo laptop that ran through the Super Fish-adware risk that their SSL traffic was intercepted, also all kinds of other programs using the same kind of certificate. That security researchers discovered Marc Rogers and Filippo Valsorda , both working for CloudFlare. The certificate used Superfish was from Komodia, an Israeli company.

The company shows the framework that for Superfish also used to have used other software. This relates to Keep My Family Secure, Easy hide IP Classic, Lavasoft Ad-aware Web Companion, Staffcop version 5.6 and 5.8, Kurupira Webfilter and Qustodio's parental control software. Also hide-my-ip is called by Rogers, only this software does not use SSL man-in-the-Middle and the certificate used is slightly different with the other programs. Yet it still uses an unrestricted root certificate with a simple password in plain text. Furthermore, the certificates Komodia for these programs used weak and the password is always Komodia.

"I think it's safe to assume that every SSL interception product sold by Komodia or Komodia SDK is based on the same method will be used," said Rogers. This means that the dangerous certificates are not only restricted to the laptops from Lenovo. Everyone who has come into contact with a product or Komodia parental control software installed check that it is not at risk.

"This problem is much bigger than we thought," warns Rogers. By using weak certificates, an attacker can eavesdrop on traffic or manipulate, without requiring users to see this. Even if the SSL connection is checked, the user sees only the strength of the connection between the Komodia software and its browser, and not the connection which goes over the internet. Users can use this page to check if it is installed on their computer, one of the Komodia certificates.
Superfish

Meanwhile Superfish puts the blame down to Komodia. The company leaves opposite the Associated Press that the vulnerability was inadvertently caused by a third party in the software. Superfish CEO Adi Pinhas also denounces the "false and misleading messages" in the media.