Changes

Jump to navigation Jump to search
422 bytes removed ,  06:16, May 6, 2017
Spelling, grammar, and general cleanup, typos fixed: transfered → transferred
Line 9: Line 9:     
===Security===
 
===Security===
−
A greater concern about Superfish is that it inserts a root certificate into the Windows certificate store, and has all SSL (secure browser traffic) communication signed using that certificate.  This is by definition a "man-in-the-middle" attack.  This enables Superfish to insert advertisements on secure pages, regardless of which browser is being used.  However, this also potentially puts the users' information at risk.  Since SSL-transfered data is not being encrypted as intended, malicious parties may have less difficulty interpreting data exchanges which were intended to be secure.  In other words, secure activity such as online banking is made easier to compromise.<ref name="pcworld.com 1">http://www.pcworld.com/article/2886357/lenovo-preinstalls-man-in-the-middle-adware-that-hijacks-https-traffic-on-new-pcs.html</ref><ref name="pcworld.com 2">http://www.pcworld.com/article/2886278/how-to-remove-the-dangerous-superfish-adware-presintalled-on-lenovo-pcs.html</ref><ref>https://www.cnet.com/news/superfish-torments-lenovo-owners-with-more-than-adware</ref>
+
A greater concern about Superfish is that it inserts a root certificate into the Windows certificate store, and has all SSL (secure browser traffic) communication signed using that certificate.  This is by definition a "man-in-the-middle" attack.  This enables Superfish to insert advertisements on secure pages, regardless of which browser is being used.  However, this also potentially puts the users' information at risk.  Since SSL-transferred data is not being encrypted as intended, malicious parties may have less difficulty interpreting data exchanges which were intended to be secure.  In other words, secure activity such as online banking is made easier to compromise.<ref name="pcworld.com 2"/><ref name="pcworld.com 1">http://www.pcworld.com/article/2886357/lenovo-preinstalls-man-in-the-middle-adware-that-hijacks-https-traffic-on-new-pcs.html</ref><ref name="cnet.com">https://www.cnet.com/news/superfish-torments-lenovo-owners-with-more-than-adware</ref>
    
==Superfish and Lenovo==
 
==Superfish and Lenovo==
−
The computer manufacturer Lenovo, formerly owned by [[IBM]], gained unwanted attention in 2014.  They were intentional installing the Superfish adware on their new laptops, without the buyers' consent. As the public became more aware of the problem, third-party software which removed superfish from Lenovo laptops became more popular.  However, damage was done to Lenovo's public image and user data was (and in some cases, still is) put at risk.  Every Lenovo device seemed to use the same weak RSA key, which means that if attackers could compromise one person's data, they could use the same exact method to compromise the data of any (and all) other Lenovo users.<ref name="pcworld.com 1">http://www.pcworld.com/article/2886357/lenovo-preinstalls-man-in-the-middle-adware-that-hijacks-https-traffic-on-new-pcs.html</ref><ref name="pcworld.com 2">http://www.pcworld.com/article/2886278/how-to-remove-the-dangerous-superfish-adware-presintalled-on-lenovo-pcs.html</ref><ref>https://www.cnet.com/news/superfish-torments-lenovo-owners-with-more-than-adware</ref>
+
The computer manufacturer Lenovo, formerly owned by [[IBM]], gained unwanted attention in 2014.  They were intentional installing the Superfish adware on their new laptops, without the buyers' consent. As the public became more aware of the problem, third-party software which removed superfish from Lenovo laptops became more popular.  However, damage was done to Lenovo's public image and user data was (and in some cases, still is) put at risk.  Every Lenovo device seemed to use the same weak RSA key, which means that if attackers could compromise one person's data, they could use the same exact method to compromise the data of any (and all) other Lenovo users.<ref name="pcworld.com 2"/><ref name="pcworld.com 1"/><ref name="cnet.com"/>
    
==References==
 
==References==
 
{{reflist}}
 
{{reflist}}
 
[[Category:Malware]]
 
[[Category:Malware]]
Block, SkipCaptcha, Automoderated users, Bots, edit
57,719

edits

Navigation menu