Kaspersky fixed an error affecting 400 million users

Kaspersky corrected a certificate validation error in her software that affected 400 millions of users.

It was discovered by Google's stubborn bug-hunter Tavis Ormandy. The flaw lies in how the company's antivirus inspects encrypted traffic.Kaspersky

As it decrypts the traffic before the inspection, Kaspersky presents her certificates as a trusted authority. If a user opens Google in his browser, for example, the certificate will appear to be from Kaspersky Anti-Virus Personal Root.

See more articles from iGuRu.gr when you search for news on Google.

The problem that Ormandy found was that the internal certificates were incredibly weak.

"As new certificates and keys are created, they are entered using the first 32 bits of 3MD5 (serialNumber || issuer) as a key… You do not need to be a cryptographer to understand that a 32bit key is not enough to prevent brute-force attacks" , says the researcher.

For error reporting Ormandy gave a PoC certificate conflict between Hacker News and manchesterct.gov:

"If you are using Kaspersky Antivirus in Manchester, and you are wondering why Hacker News does not work sometimes, it is because a critical vulnerability has disabled SSL authentication for 400 million Kaspersky users."

Kaspersky reportedly corrected the 28 December error.

Kaspersky: SSL interception differentiates certificates with a 32bit hash


Google preferences

Leave a Comment

Your email address will not be published. Required fields are marked *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).