That is either by using the "connected version" or loosing the multi devices ability. BTW shouldn't the "connected version" be the one detailed on the home page? Sure sounds more attractive to me.
HN user
HackinOut
Benjamin Guesneau
Twitter: @HackinOut
I wouldn't use a password manager system that doesn't have the ability to change the master password.
EDIT: You can't change any password really, without changing all of them (or having a separate master password). Seems unpractical as soon as, for example, site X gets its database hacked.
I can't believe Nigel Farage and a lot of pro Brexit campaigners have been calling it UK's "Independence day". Apart from being a very bad (purposeful?) analogy, it's seems to me pretty disrespectful to their own and to US history. I'm not from USA (or UK) but would love to hear how US and UK people feel about it?
Not aware of anything from Apple about this issue. It was just an assumption, sorry. What I did is test up to date devices (i think i even tested an up to date iOS 6) and couldn't get any specific SSID. The probe requests were still there, but SSID parameter was always set to Broadcast.
However I did see a lots of probe requests WITH a SSID parameter set but those were not coming from my devices :). I assumed they were not up to date.
I am very interested to know if the probe requests you're seeing are also coming from unknown devices: if they aren't, could you provide us with the iOS version you're using/testing with?
It doesn't seems to be iOS 8 only. Recent versions of iOS 7 seem to be fixed as well. (Tested my phone earlier this week)
My iPhone do connect auto-magically to FreeWifi_secure networks which is the preloaded SSID for the other french operator listed by Skycure.
However it's supposed to connect with EAP-SIM [1]. Skycure mentions that "some of [those] bundles include SSID passwords". Do they mean that only those would make devices vulnerable? Could you let us know if SFR uses EAP-SIM or a basic PSK?
It could be that iPhones connect automatically only to EAP-SIM preloaded networks.
(because iOS devices broadcast this when scanning for networks IIRC?)
Not anymore, Apple fixed that in recent iOS versions. Probe requests are not divulging SSIDs anymore. However WifiGate uses common SSIDs and network operators preloaded ones as honeypots.
Good point for Apple. But I wouldn't call having your computer fixed 4 times in ~2 months lucky... Every brand seems to be having reliability problems with their products nowadays (in software as well as hardware). More than in the past. Or maybe it's just me, unlucky as you are... I really have no idea what my next laptop will be...
Double standards are also seen in their "Removal Instructions" post on their forum. When uninstalling SuperFish, it seems suddenly important to remove the root certificate...
"It is very important to delete the certificate even though the application itself has been removed."
http://forums.lenovo.com/t5/Lenovo-P-Y-and-Z-series/Removal-...
Didn't seem that important earlier today: https://web.archive.org/web/20150219151726/http://forums.len...
"files in user directory will stay intact for the privacy reason. Registry entry and root certificate will remain as well. "
Komodia, the company behind the tech contracted by the maker of SuperFish, actually (tries) to makes sure invalid and self-signed certificate do generates a warning in the browser. And then they password protect the private key with... the name of their company?!?
http://www.komodia.com/wiki/index.php?title=SSL_Digestor#Cer...
"Also the module tries to verify that the certificate is indeed signed by an approved signer, it will use the CA store of the browser used to verify that (for Internet Explorer the Windows store will be used, and for Firefox the NSS store will be used), if the certificate isn't legit, the created certificate will be created in a way it would raise an alert to protect the user."
A huge ugly hack...
"We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns."
http://forums.lenovo.com/t5/Lenovo-P-Y-and-Z-series/Removal-...
"This article will be updated with additional instructions on clean up of deactivated files and removal of certificate shortly."
This was just edited in, here is the post before that: https://web.archive.org/web/20150219151726/http://forums.len...
So, Lenovo, why should we remove this certificate after all? Any security concerns perhaps?
Wow...
Now Lenovo is "soon" going to explain how to remove this certificate after the "uninstall" in a buried forum post...
http://forums.lenovo.com/t5/Lenovo-P-Y-and-Z-series/Removal-...
"This article will be updated with additional instructions on clean up of deactivated files and removal of certificate shortly."
This was just edited, here is the post before that: https://web.archive.org/web/20150219151726/http://forums.len...
Not if the proxy checks the certificate of the site it's connecting to and doesn't trust it's own self-signed cert (there is no point in doing so if it's pure adware). But yeah... I have no idea what it does...
Except if the adware just modify OS proxy settings, like madeofpalk mentioned. Firefox does not take those into account.
It does not. Firefox has it's own implementation, which is pretty great (supports all kind of proxies/socks).
"Someone will extract the private key in the next few hours, and then HTTPS will be basically completely broken for all Lenovo users -- anyone will be able to spoof any site to them."
Do you mean the proxy is remote? That is not the impression I have (otherwise having the private key locally makes no sense).
If it's local, then even with the private key extracted, and considering a lot of website force https nowadays, we should still have standard crypto between the lenovo computer and the website. EDIT: As long as the adware checks the website certificate AND doesn't trust it's own self-signed certificate in the store... yeah... a lot of ifs...
Anyway, thanks for the additional details, more helpful than "[...] the certificate allows the software to decrypt secure requests[...]", found in the article...
TheNextWeb does a poor job at reporting technical facts:
"[...] its own self-signed certificate authority which effectively allows the software to snoop on secure connections [...]"
"[...] the certificate allows the software to decrypt secure requests[...]"
As kentonv reported, it's actually the local proxy, installed by the ad(Mal?)ware which is at the center of the MiTM attack. The root, self-signed certificate is installed in order for the attack to be transparent to the victim (i.e. no warning in browser).
Before this went down, the highest recorded fold was at 987654px. Somebody had fun with the experiment or has a nice 1755K screen :)
Most viruses are identified by their signature only, because most of them are dumb. Heuristics for unknown threats are often there purely for marketing.
AVs have all more or less the same signature database due to the same reason as above, most viruses are dumb and well known (most can't even be called viruses, think adware & co). IMO this the best reason for not having multiple AVs. I personally do not trust an AV for anything more than dumb signature checking (which are easily circumvented with polymorphism or sometime encryption alone) and targeted heuristics.
I also don't even want to start thinking at the mess that could be created by several AVs's injection/hooking mechanisms on the same machine.
"Grid fins worked extremely well from hypersonic velocity to subsonic, but ran out of hydraulic fluid right before landing."
"Upcoming flight already has 50% more hydraulic fluid, so should have plenty of margin for landing attempt next month."
I would expect that even if it wasn't mentioned, I mean it's a freaking internet access in a fast moving object 30,000 feet above ground! I don't like what Gogo just did, but kudos for undertaking this challenge. barnaby mentioned they have in-flight paid media services, of what sort/diversity/quality? I suppose it's a selection of movies stored on a server in the plane.
1) They are not blocking (completely) Youtube. But still plausible.
2) Then why would they be doing it only on video streaming websites? [1] Also, if they are so obvious about their methods from now on, one nice thing is that we won't need whistleblowers anymore.
Sounds like good news. I can understand why they would choose amazon payments since amazon has more credit cards on file than anybody else including Paypal. But Amazon payments or Paypal (I am not referring to their gateway offering) is often something you use to complement a more classical credit card processor (i.e. users are able to input their CC infos directly on your site) like Stripe or Authorize.net. I really do not understand, until now, their choice of going exclusively with Amazon Payments for all this time. Preferred rates maybe?
Back to the Future was slightly off :)
I love electric vehicles of all sorts, let's enjoy them to the fullest, the hoverboard will be there soon enough.
According to tweet author[1], this happened only with Youtube, and was not related to captive portal mechanism whatsoever. So I would side with her on the why: Poor plane internet access was overloaded by videos streamed from Youtube and somebody hacked together a very ugly solution that's going to have bad consequences...
Well they would be facing the unforeseen consequences while not even filtering the HTTP host header (the youtube page is displayed). Unless they forgot to disable the MITM once the user is granted full internet access...
EDIT: Those are two nice insights about what Gogo does behind the scene, but I would bet the fact Google is involved with both is a coincidence (or is it considering the multiplicity of Google's Services?)
it doesn't redirect to the signup page. i believe it's to throttle streaming, but there are better ways to do it
https://twitter.com/__apf__/status/551132865555996673
EDIT: Still from same author:
no, had already been logged in for hours; and only happened on YouTube
* asymmetric key pair
I think "Phase 3" is indeed too much. I would think this tool would be more useful for "simple" MITM than for PSK phishing.