Web Hack List

Collected research

Superfish SSL MitM

Lenovo PCs ship with man-in-the-middle adware that breaks HTTPS connections [Updated]

Lenovo consumer laptops shipped with Superfish ad-injection software that installs its own root certificate and proxies HTTPS, and the accompanying private key is identical on every machine and protected by the password komodia. Anyone who extracts it can present forged certificates for any site to affected PCs, and Chrome key pinning does not warn because the anchor is locally installed.

Record

Document
Lenovo PCs ship with man-in-the-middle adware that breaks HTTPS connections [Updated]
Researcher
Dan Goodin
Published by
Ars Technica
Date
Topic
Crypto

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Dan Goodin, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .