Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

MITMing your own SSL connections can be done safely, and for good reasons (Charles proxy being a good example of both). These guys are doing it unsafely, and for bad reasons. However, those two parts are unrelated! This stuff could easily have been safe had they known what they were doing, or prioritized that. I don't think it's fair to say that the security hole itself is intentional. Certainly if they hadn't built the product in the first place the hole wouldn't exist, but building the product doesn't imply the hole had to be there.

The fundamental problem is that software like this greatly increases your attack surface, and thus should only be used with careful consideration if the benefits are worthwhile. Instead, Lenovo put its users at risk without informing them or providing them with any benefit.



Yes, another use-case is if you are running Privoxy on your local computer; would be great if you could MITM all local SSL connections instead of having to manually whitelist specific sites.


Here's how to decrypt ssl sessions in Wireshark

https://jimshaver.net/2015/02/11/decrypting-tls-browser-traf...

Before that I used Burpsuite, but that uses its own self signed cert too.

http://portswigger.net/burp/

Privoxy doesn't do SSL or did I miss something?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: