Download.com and Other Sites Bundling Superfish-Style Adware: Report

Advertisement
By Hitesh Arora | Updated: 25 February 2015 16:59 IST
Despite new security features being added on an almost daily basis, we are certainly not moving towards a more secure Internet - at least, this is what can be derived from recent findings.

After Lenovo was found to be installing the malicious adware Superfish in consumer machines, another report on Monday came out suggesting that it is not the only one doing it. It reported two names of the security firms that have added similar man-in-the-middle code in their software platforms. While one software is being said to be using vulnerable SSL-interception technology sold by Komodia, similar to what Superfish employed, the other using different technology achieves the same effect of bypassing SSL and HTTPS protection.

All this seems to have created panic in consumers, and researchers are taking concerns seriously. According to a new report by How to Geek on Monday, several freeware and software sites (including CNET's Download.com) are bundling HTTPS-breaking-adware nowadays.

The report notes that the adware like Wajam, Geniusbox, Content Explorer, and many others are following the same trend as seen with Superfish in Lenovo. These companies are installing their own certificates and forcing all your browsing (including HTTPS encrypted browsing sessions) to go through their proxy server. Not just that, the report claims that your machine can just get infected "by installing two [KMPlayer and YTD] of the top 10 apps on CNET Downloads." The two apps reportedly feature two different types of "HTTPS-hijacking adware".

Advertisement

Once the adware is installed and is proxying all the traffic, users start to see ads all over even on the secure sites, like on Google, "replacing the actual Google ads, or they show up as popups all over the place, taking over every site."

Advertisement

These adware essentially install their fake root certificates into the Windows Certificates store and then use proxies to connect to secure sites with the fake certificates, explains report.

While it is not exactly clear whether the Download.com team or the app developers are bundling the adware, the distribution sites are obligated to ensure the content they host is safe.

Advertisement

So in short, the HTTPS websites are also not secure if any adware is installed on your machine knowingly or unknowingly.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. OPPO K13 Turbo 5G Series Overview: Definitely a Flagship Choice for Gamers Under Rs. 40,000
  2. Realme 15T 5G India Launch Today: All You Need to Know
  3. Flipkart Big Billion Days Sale 2025 in India Announced
  4. Amazon Great Indian Festival Sale to Begin Soon; Bank Discounts Revealed
  5. Washable Fiber Computer Could Transform the Future of Smart Clothing, Study Finds
  6. OnePlus Pad 3 Price in India, Offers Announced Ahead of September 5 Debut
  7. Saiyaara is All Set to Stream on This OTT Platform in September
  8. OnePlus 15 Design Leaked; Could Launch in These Three Colourways
  9. Amazon Great Indian Festival Sale 2025: Top Deals on Electronics Revealed
  1. Apple Hebbal, Bengaluru’s first Apple Store, Opens Today
  2. Vivo Y500 Launched With 120Hz AMOLED Screen and 8,200mAh Battery: Price, Specifications
  3. Realme 15T 5G Launching Today: Know Price in India, Features, Specifications and More
  4. Washable Fiber Computer Could Transform the Future of Smart Clothing, Study Finds
  5. Who Is Megan McArthur, the First Woman to Pilot NASA's SpaceX Dragon?
  6. Rajkummar Rao's Maalik Set for OTT Release: Know When, Where to Watch Online
  7. ISS Crew Studies Bone Loss and Brain Adaptation to Safeguard Astronaut Health
  8. ESA’s JUICE Probe Uses Venus Flyby to Stay on Track for Jupiter’s Icy Moons
  9. Saiyaara OTT Release: Know When and Where to Watch Ahaan Pandey, Aneet Padda-Starring Blockbuster Film Online
  10. NASA Unveils Plans for Lunar Nuclear Reactor by 2030 Amid Rising Moon Race
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.