Security Software Found Using Superfish-Style Code: Report

Advertisement
By NDTV Correspondent | Updated: 23 February 2015 21:08 IST
After Lenovo was found to be installing malicious software called Superfish on consumer PCs , a new report has come out suggesting two security firms have added similar man-in-the-middle code in their software platforms. While one software is being said to be using vulnerable SSL-interception technology sold by Komodia, similar to what Superfish employed, the other using different technology achieves the same effect of bypassing SSL and HTTPS protection.

As discovered over the weekend by security researcher Filippo Valsorda (via ArsTechnica), software by the antivirus company Lavasoft, features vulnerable Komodia code (Komodia SSL Digestor) that issues root certificates allowing most browsers to trust any self-signed certificate, allowing hackers to forge trusted credentials for any HTTPS-protected webstie.

According to Valsorda, Lavasoft's Ad-aware Web Companion comes with the vulnerable code. The company says it is unable to confirm if the vulnerable Komodia code has been fully removed from the latest version of its Ad-aware Web Companion software, and will release an update if required.

On the other hand, the CEO of certificate authority Comodo (a company that Ars Technica says issues roughly one-third of the Internet's Transport Layer Security certificates) recently released PrivDog software that replaces ads with ads from trusted sources. According to Valsorda, PrivDog features code that fools most browsers into trusting any self-signed certificate, allowing for man-in-the-middle attacks that completely bypass HTTPS protection. It is said not to use Komodia's technology.

Advertisement

Meanwhile, Superfish CEO Adi Pinhas via email admitted to The Next Web that the company intentionally installed the root certificate authority in its Visual Browser software to "enable a search from any site" and serve better ads. The CEO went on to say the threat of the certificate was not known until security reports surfaced. Pinhas added the Superfish software is currently being used by 40 million users.

 

Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.

Further reading: Apps, Comodo, Laptops, Lavasoft, Lenovo, PC, PrivDog, Superfish
Advertisement

Related Stories

Popular Mobile Brands
  1. Arc Raiders Will Get Multiple New Maps This Year, Says Embark
  2. iQOO 15 Ultra Teaser Hints at Launch Date, Active Cooling Support
  3. Samsung Galaxy S26 Ultra Colourways Spotted in Leaked SIM Tray Images
  4. Here's How Much the Realme P4 Power Could Cost in India
  5. Oakley Meta HSTN Smart Glasses Review
  6. Viruses and Bacteria Evolve Differently in Space, ISS Study Finds
  7. Sarvam Maya OTT Release: Know Everything About This Malayalam Fantasy Drama Film
  8. Amazon Great Republic Day Sale: Best Deals on Printers Under Rs. 10,000
  9. Samsung Galaxy Z Fold 8 May Sport a Smaller Crease Using This Technology
  1. Global RAM Shortage Is Reportedly Causing GPU, Storage Drive Prices to Skyrocket
  2. Viruses and Bacteria Evolve Differently in Space, ISS Study Finds
  3. Rockstar Games Said to Have Granted a Terminally Ill Fan's Wish to Play GTA 6
  4. Oppo K15 Turbo Series Tipped to Feature Built-in Cooling Fans; Oppo K15 Pro Model Said to Get MediaTek Chipset
  5. Samsung Galaxy Z Fold 8 Said to Feature Dual Ultra-Thin Glass OLED Panel to Reduce Crease Visibility
  6. Honor Magic 8 Pro Air Launched Alongside Honor Magic 8 RSR Porsche Design: Price, Specifications
  7. Realme Neo 8 Key Specifications Including 8,000mAh Battery, Ultrasonic Fingerprint Sensor Confirmed
  8. Astronomers Find Massive Iron-Rich Feature Lurking Under the Ring Nebula
  9. Asus Reportedly Halts Smartphone Launches ‘Temporarily’ to Focus on AI Robots, Smart Glasses
  10. JioHotstar Announces Monthly Subscription Plans Across Mobile, Super, and Premium Tiers
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.