Are there other options besides installing my own root certificate?
Assuming I want to write software that legitimately MITMs all HTTP and HTTPS traffic (parental control, ad blocker, anti-virus scan for webpages...). I want it to be browser independent and work with browsers that don't support extensions.
Komodia’s Watchdog
The Kernel protection watchdog is used to protect Komodia’s Redirector files from being deleted/modified, lsp from being uninstalled and also protects the main process will not be stopped.
But when you do so, you assume big responsibilities. You have to do all the stuff the browser does, and even lots of security people, if you sat them down and told them to write everything a browser does, would probably forget a few important things. (The browser security folks are exceptions.)
The top post on this page ('patcheudor) is from a researcher who reports that Superfish wasn't doing proper validation of certs, meaning we didn't even need to extract the private key from the binary to forge www.paypal.com.
If I spun up a stupid fake cert for www.paypal.com last week, with no knowledge of Superfish whatsoever, someone from a Lenovo computer would not get certificate warnings.
The more people look at this, the worse it gets. It's a fractal of bad security.
They have the choice of having HTTPS effectively useless (by leaving the certificate there), or making HTTPS not work (by removing it, thus prompting action from the user to fix it -- perhaps by calling their tech savvy nephew).
Browser vendors should (and usually do) err on the side of security.
https://twitter.com/matthew_d_green/status/56843703790644428...
Probably not a proxy; probably low-level socket interception in Windows.
So there isn't much the browsers can do to help the user.
At least the technical side of Lenovo's response is all the way to "We are writing a program to remove the certificates", which is probably the thing that is going to impact the most people.