This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Community Information

Comodo accused, shipping adware worse than Superfish

1 min read

This thread's last reply is from June 1, 2015, 5:11 AM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

Comodo accused of shipping adware that’s worse than Superfish, breaks HTTPS security
http://siliconangle.com/blog/2015/02/22 ... -security/

Johannes Bock claims on his blog that Privdog does something that’s worse than Superfish: it breaks HTTPS by allowing through any sort of certificate, signed or not. In his words:
While Superfish uses the same certificate and key on all hosts PrivDog recreates a key/cert on every installation. However here comes the big flaw: PrivDog will intercept every certificate and replace it with one signed by its root key. And that means also certificates that weren’t valid in the first place. It will turn your Browser into one that just accepts every HTTPS certificate out there, whether it’s been signed by a certificate authority or not.


Additional articles:
http://www.theregister.co.uk/2015/02/24 ... l_privdog/

Test to see if your vulnerable:
https://filippo.io/Badfish/
zb