logo

Update: Superfish is the Real End of SSL

ID: f57c06d8-90a5-54ed-bc6c-a8330e29424d

STIX ID: report--f57c06d8-90a5-54ed-bc6c-a8330e29424d

Feed Name: Security Ledger

Threat Score
75/100

Date Published: 2015-02-23

Date Updated: 2026-05-08

Author: Paul Roberts

...
...

The report details how preinstalled Superfish adware on Lenovo consumer laptops used the Komodia library to install a root certificate and private key, enabling interception and decryption of SSL/TLS sessions (a machine-level MITM). Researchers extracted and cracked the private key, demonstrated practical attack scenarios, and the story is used to illustrate wider failures in the CA/PKI trust model and similar risks from other applications performing SSL interception.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.