Update: Superfish is the Real End of SSL
ID: f57c06d8-90a5-54ed-bc6c-a8330e29424d
STIX ID: report--f57c06d8-90a5-54ed-bc6c-a8330e29424d
Feed Name: Security Ledger
Threat Score
The report details how preinstalled Superfish adware on Lenovo consumer laptops used the Komodia library to install a root certificate and private key, enabling interception and decryption of SSL/TLS sessions (a machine-level MITM). Researchers extracted and cracked the private key, demonstrated practical attack scenarios, and the story is used to illustrate wider failures in the CA/PKI trust model and similar risks from other applications performing SSL interception.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
