Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Why is Superfish getting all of the heat, while Komodia gets comparatively very little?

A product that injects ads in your web traffic is crapware, but the scandal here isn't that superfish was crapware, the scandal is the security hole it introduced, which compromised Lenovo users. Yes, we all hate crapware, but there's a big difference between bothering people with sneaky, unwanted, ads, and opening the doors for malicious parties to intercept their online banking credentials.

However, a SSL intercepting software does not need to expose such a security flaw. It was only Komodia's moronic implementation which did so. If instead of using a fixed private CA key, they had generated one on the fly when the software is run for the first time, users wouldn't have been exposed.

Regarding the VCs, I would give them the benefit of the doubt as well. What where they pitched? SuperFish was about shopping using image recognition. For all I know, they raised money on a pitch about offering a search service, and then ended up pivoting. I don't know for sure if that's the case, but it's possible, and the VCs should get a chance to tell their side of the story before being dragged in the mud.



It's not just that Komodia used the same root cert. It goes a bit deeper than that: https://blog.filippo.io/komodia-superfish-ssl-validation-is-...



I was wondering if they even did the validation properly on the Internet facing side. Turns out they don't, wow.


Injecting ads into traffic is basically stealing advertising space from websites. They should sue the living shit out of Lenovo.


That seems like a bad precedent, I don't want my ad-blocker getting sued into oblivion because then I'd have to see ads online... :)




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: