Kaspersky fixed an error affecting 400 million users

Kaspersky corrected a certificate validation error in her software that affected 400 millions of users.

Discovered by persistent bug- Tavis Ormandy της Google. Το ελάττωμα έγκειται στο πώς το antivirus της εταιρείας επιθεωρεί την κρυπτογραφημένη κίνηση.Kaspersky

Since it decrypts traffic before inspection, Kaspersky presents its certificates as a trusted authority. If a user opens Google in their browser, for example, the certificate will appear to come from Kaspersky Anti-Virus Root.

The problem that Ormandy found was that the internal certificates were incredibly weak.

“As the new certificates are created and the , they enter using the first 32 bits of 3MD5(serialNumber||issuer) as a key … You don't need to be a cryptographer to understand that a 32-bit key is not enough for brute-force attacks", says the researcher.

For error reporting Ormandy gave a PoC certificate conflict between Hacker News and manchesterct.gov:

"If you're using Kaspersky Antivirus in Manchester, and you're wondering why Hacker News doesn't work sometimes, it's because a critical disabled SSL certificate validation for 400 million Kaspersky users.”

Kaspersky reportedly corrected the 28 December error.

Kaspersky: SSL interception differentiates certificates with a 32bit hash

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.082 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).