140 karma · joined May 5, 2014
Twitter: @HackinOut
EDIT: You can't change any password really, without changing all of them (or having a separate master password). Seems unpractical as soon as, for example, site X gets its database hacked.
However I did see a lots of probe requests WITH a SSID parameter set but those were not coming from my devices :). I assumed they were not up to date.
I am very interested to know if the probe requests you're seeing are also coming from unknown devices: if they aren't, could you provide us with the iOS version you're using/testing with?
However it's supposed to connect with EAP-SIM [1]. Skycure mentions that "some of [those] bundles include SSID passwords". Do they mean that only those would make devices vulnerable? Could you let us know if SFR uses EAP-SIM or a basic PSK?
It could be that iPhones connect automatically only to EAP-SIM preloaded networks.
Not anymore, Apple fixed that in recent iOS versions. Probe requests are not divulging SSIDs anymore. However WifiGate uses common SSIDs and network operators preloaded ones as honeypots.
"It is very important to delete the certificate even though the application itself has been removed."
http://forums.lenovo.com/t5/Lenovo-P-Y-and-Z-series/Removal-...
Didn't seem that important earlier today: https://web.archive.org/web/20150219151726/http://forums.len...
"files in user directory will stay intact for the privacy reason. Registry entry and root certificate will remain as well. "
http://www.komodia.com/wiki/index.php?title=SSL_Digestor#Cer...
"Also the module tries to verify that the certificate is indeed signed by an approved signer, it will use the CA store of the browser used to verify that (for Internet Explorer the Windows store will be used, and for Firefox the NSS store will be used), if the certificate isn't legit, the created certificate will be created in a way it would raise an alert to protect the user."
A huge ugly hack...
http://forums.lenovo.com/t5/Lenovo-P-Y-and-Z-series/Removal-...
"This article will be updated with additional instructions on clean up of deactivated files and removal of certificate shortly."
This was just edited in, here is the post before that: https://web.archive.org/web/20150219151726/http://forums.len...
So, Lenovo, why should we remove this certificate after all? Any security concerns perhaps?
Now Lenovo is "soon" going to explain how to remove this certificate after the "uninstall" in a buried forum post...
http://forums.lenovo.com/t5/Lenovo-P-Y-and-Z-series/Removal-...
This was just edited, here is the post before that: https://web.archive.org/web/20150219151726/http://forums.len...
Do you mean the proxy is remote? That is not the impression I have (otherwise having the private key locally makes no sense).
If it's local, then even with the private key extracted, and considering a lot of website force https nowadays, we should still have standard crypto between the lenovo computer and the website. EDIT: As long as the adware checks the website certificate AND doesn't trust it's own self-signed certificate in the store... yeah... a lot of ifs...
Anyway, thanks for the additional details, more helpful than "[...] the certificate allows the software to decrypt secure requests[...]", found in the article...
"[...] its own self-signed certificate authority which effectively allows the software to snoop on secure connections [...]"
"[...] the certificate allows the software to decrypt secure requests[...]"
As kentonv reported, it's actually the local proxy, installed by the ad(Mal?)ware which is at the center of the MiTM attack. The root, self-signed certificate is installed in order for the attack to be transparent to the victim (i.e. no warning in browser).
AVs have all more or less the same signature database due to the same reason as above, most viruses are dumb and well known (most can't even be called viruses, think adware & co). IMO this the best reason for not having multiple AVs. I personally do not trust an AV for anything more than dumb signature checking (which are easily circumvented with polymorphism or sometime encryption alone) and targeted heuristics.
I also don't even want to start thinking at the mess that could be created by several AVs's injection/hooking mechanisms on the same machine.
"Upcoming flight already has 50% more hydraulic fluid, so should have plenty of margin for landing attempt next month."
2) Then why would they be doing it only on video streaming websites? [1] Also, if they are so obvious about their methods from now on, one nice thing is that we won't need whistleblowers anymore.
I love electric vehicles of all sorts, let's enjoy them to the fullest, the hoverboard will be there soon enough.
EDIT: Those are two nice insights about what Gogo does behind the scene, but I would bet the fact Google is involved with both is a coincidence (or is it considering the multiplicity of Google's Services?)
https://twitter.com/__apf__/status/551132865555996673
EDIT: Still from same author:
no, had already been logged in for hours; and only happened on YouTube