Windows 10: Lenovo PCs ship with man-in-the-middle adware that breaks HTTPS Connec

Discus and support Lenovo PCs ship with man-in-the-middle adware that breaks HTTPS Connec in Windows 10 News to solve the problem; OK, that works good also. How can we tell if all these other certs listed are spies or not ? A lot of them I never heard of, but why do I need one for... Discussion in 'Windows 10 News' started by ARC1020, Feb 18, 2015.

  1. Dude Win User

    Lenovo PCs ship with man-in-the-middle adware that breaks HTTPS Connec


    That is probably a ssl certificate from a shopping site Go Daddy is a privately held Internet domain registrar and web hosting company. Yep, and probably a site he has shopped at goes through go daddy


    SSL-Zertifikat | mehr Schutz für Ihre Daten - GoDaddy DE
     
  2. z3r010 Win User

    Godaddy also sell/issue ssl,the ones we use from time to time are listed as godaddy.
     
    z3r010, Feb 18, 2015
    #17
  3. Never been to a Go Daddy site. I used this as an example.
    Is there any way to tell if any of these certificates, going by any name, should be deleted ?
     
    COMPUTIAC Guest, Feb 18, 2015
    #18
  4. z3r010 Win User

    Lenovo PCs ship with man-in-the-middle adware that breaks HTTPS Connec

    But godaddy sign the certificates it could be any old random site, you wouldn't know unless you checked every sites SSL when you visited it.

    I think they also do shared SSL that would also show their name.
     
    z3r010, Feb 18, 2015
    #19
  5. ARC1020 Win User
    Official [and insufficient at the moment] Lenovo Visual Disc​overy/Superfish removal instructions can be found at the following link:
    Removal Instructions for VisualDiscovery Superfish... - Lenovo Community

    Note text at the bottom, which reads "...this article will be updated with additional instructions on clean up of deactivated files and removal of certificate shortly". (Athough it's been like that for quite a while now).

    ------

    You can however find unofficial removal instructions at the following link:
    How to remove Superfish
     
    ARC1020, Feb 19, 2015
    #20
  6. Mystere Win User
    Please do not go randomly deleting things without first having some idea whether you should or not. Clearly, the superfish cert should be removed, but don't go removing other ones because you think "I don't use those". You may or may not, but you wouldn't know if you did.

    Those are "Root Certificates", and are the public key certificates that root certificate authorities issue that allow you to decode the encrypted traffic (HTTPS) from banks, shopping sites, or pretty much anything that uses HTTPS from an authority. They purchase their certs from GoDaddy or other vendors who sign those certficates with their private keys. This gives you the ability to decode those keys for sites that have bought certificates from them, and they could literally be anyone.

    So unless you want to suddenly start getting certificate errors and/or not be able to use random sites on the internet for no apparent reason, don't just go deleting these without very good knowledge of what you are doing.
     
    Mystere, Feb 19, 2015
    #21
  7. ARC1020 Win User
    Not that I'm aware of. One of the weaknesses with Public Key Infrastructure is that you have to trust Certificate Authorities.

    Which as previously seen with breaches of Comodo CA, DigiNotar CA, etc. that isn't always the case.
     
    ARC1020, Feb 19, 2015
    #22
  8. ARC1020 Win User

    Lenovo PCs ship with man-in-the-middle adware that breaks HTTPS Connec

    Going off on a bit of a tangent, but in addition to the above post, although the Ars Technica article says certificate pinning in Google Chrome will do nothing to alert users that something is amiss, IF you're techie minded and don't mind experimenting/reading up on headache inducing techie subjects, you could possibly use the Certificate Pinning feature in EMET 5.1 for the main websites that you care about logging into securely (If you use Internet Explorer). Details on Certificate Pinning can be found in the EMET User Guide (the 'Download' button HERE will give you the option to download the User Guide on it's own).

    With EMET Certificate Pinning you can manually add (pin) a root certificate to be used for a particular website. For example, I could tell it to only allow VeriSign root certificate (Serial Number:18DAD19E267DE8BB4A2158CDCC6B3B4A) for signin.ebay.co.uk. Although EMET wouldn't prevent me from visiting and using signin.ebay.co.uk, if the certificate for that domain was signed by a different root certificate (such as Superfish), it should display a small notification in the bottom right corner of the screen telling me the root certificate is different to the one I specified.

    As an example, for the purpose of this post, in the below screenshot I specified a different root certificate in EMET to the one that was actually used to sign the current signin.ebay.co.uk SSL certificate, and you can see the EMET warning in the bottom right notifying me of the certificate mismatch (which needs to be bigger really and a different colour, as it's too easy to miss on a big screen).


    Lenovo PCs ship with man-in-the-middle adware that breaks HTTPS Connec [​IMG]



    Obviously, if you're being MITM'd, before specifying which root certificate to pin you need a way to check a websites certificate to know what the correct certificate should actually be. One way to do this is Steve Gibson has a lookup on his website (GRC | SSL TLS HTTPS Web Server Certificate Fingerprints  ) that will show what the correct thumbprint for the website certificate should be. Bear in mind, these GRC thumbprints are for the website certificate, not the root certificate at the top of the tree which is what you actually specify in EMET. And also, as mentioned at the bottom of the GRC page, you still need to be vigilant because if the MITM is able to intercept your encrypted traffic, it could potentially also modify the GRC page contents. It's turtles all the way down... FYI, root certificate is shown in Certification Path tab.


    Lenovo PCs ship with man-in-the-middle adware that breaks HTTPS Connec [​IMG]



    Now, EMET Cert Pinning is way overkill and isn't something a normal user would do, as it's a manual process (which is a pain), you need to learn how to use it (which is a pain) and it also needs to be updated manually (which is a pain). Even I got fed up with manually updating it every time a certificate expired, so now-a-days I just set all the expiry dates to 2016. Therefore I only get notifications if the root certificate changes now. It's also not something that you can roll out to other users either because they'll just ignore the warning anyway. Now, if there was a way that Microsoft could automate certificate pinning in Windows 10 though, so that no user interaction is required...
     
    ARC1020, Feb 19, 2015
    #23
  9. labeeman Win User
  10. ARC1020 Win User
    ARC1020, Feb 19, 2015
    #25
  11. COMPUTIAC Guest, Feb 24, 2015
    #26
  12. I read (somewhere ) today or yesterday Lenovo is going to start emphasizing clean PC's *something kinda like Microsoft signature PC's in their marketing . ofc nothing beats a clean install on a new box ☺
     
    blutos cousin, Feb 24, 2015
    #27
  13. ARC1020 Win User

    Lenovo PCs ship with man-in-the-middle adware that breaks HTTPS Connec

    It looks like from today Ten Forums have HTTPS throughout their site with an EV cert now. No idea who this 'Superfish' CA is though... I'm joking!!! *Biggrin *Biggrin *Biggrin


    Lenovo PCs ship with man-in-the-middle adware that breaks HTTPS Connec [​IMG]
     
    ARC1020, Apr 4, 2018
    #28
Thema:

Lenovo PCs ship with man-in-the-middle adware that breaks HTTPS Connec

Loading...
  1. Lenovo PCs ship with man-in-the-middle adware that breaks HTTPS Connec - Similar Threads - Lenovo PCs ship

  2. Adware

    in AntiVirus, Firewalls and System Security
    Adware: Please help! Urgent!Adwcleaner found 6 items!Pup. Optional Assistant 1 itemPup.optional.Legacy 4 itemsPup.optional.mediaget 1 itemWhen I press next, I see preinstalled software which comes from Acer.I dont know what to do!Help me delete! Please help!!...
  3. LENOVO pcs, or other pcs crashing for no reason.

    in Windows 10 Gaming
    LENOVO pcs, or other pcs crashing for no reason.: Hi, I have fixed this a while ago, thought I would suggest a way to fix it! Firstly, I experienced issues crashing, whether in a game or watching a video, attending class. ETC. It would always freeze, make this annoying buzzing sound and the only way to fix it/ get out of it...
  4. LENOVO pcs, or other pcs crashing for no reason.

    in Windows 10 Software and Apps
    LENOVO pcs, or other pcs crashing for no reason.: Hi, I have fixed this a while ago, thought I would suggest a way to fix it! Firstly, I experienced issues crashing, whether in a game or watching a video, attending class. ETC. It would always freeze, make this annoying buzzing sound and the only way to fix it/ get out of it...
  5. LENOVO pcs, or other pcs crashing for no reason.

    in Windows 10 Drivers and Hardware
    LENOVO pcs, or other pcs crashing for no reason.: Hi, I have fixed this a while ago, thought I would suggest a way to fix it! Firstly, I experienced issues crashing, whether in a game or watching a video, attending class. ETC. It would always freeze, make this annoying buzzing sound and the only way to fix it/ get out of it...
  6. NAS connecivity gets disrupted

    in Windows 10 Network and Sharing
    NAS connecivity gets disrupted: Hi. The office that I work in has a NAS system which we use to store our files and directly access them for all our working needs. The files are of Cad Drafting, 3d modelling, etc. architectural design mostly. There are around 5-6 active computers that are connected to NAS...
  7. Google - Better protection against Man in the Middle phishing attacks

    in Windows 10 News
    Google - Better protection against Man in the Middle phishing attacks: We’re constantly working to improve our phishing protections to keep your information secure. Last year, we announced that we would require JavaScript to be enabled in your browser when you sign in so that we can run a risk assessment whenever credentials are entered on a...
  8. Bios Update LENOVO pcs

    in Windows 10 BSOD Crashes and Debugging
    Bios Update LENOVO pcs: Lenovo recently release a BIOS update to all the computer and from that release some computers are having issue with the peripheral like keyboard printers mouse even displays for desktop computer so in this case contact LENOVO and ask for a BIOS update and after the update...
  9. Microsoft Improves Win Security with Man-in-the-Middle Adware Block

    in Windows 10 News
    Microsoft Improves Win Security with Man-in-the-Middle Adware Block: Keeping browsing experience in users’ hands In April last year we announced some changes to our criteria around Adware designed to ensure that users maintain control of their experience. These changes are described in our blog, Adware: a New Approach. Since then, we’ve...
  10. Microsoft ships first Windows 10 upgrade to corporate PCs

    in Windows 10 News
    Microsoft ships first Windows 10 upgrade to corporate PCs: Microsoft ships first Windows 10 upgrade to corporate PCs [img] Credit: Microsoft 'Current Branch for Business' release signals slower pace and uncertain schedule By Gregg Keizer Follow Computerworld | Apr 11, 2016 6:49 AM PT Microsoft last week promoted Windows...