Author Topic: Certification mismatch and Poodle vulnerability for Qualcomm website CDN.  (Read 998 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Various hick-ups for big wireless tech site: What insecurity we detect on this website
Re: https://observatory.mozilla.org/analyze.html?host=www.qualcomm.com (F-grade status and recommendations there).

On the insecurity on the non-public Akamai CDN for this website: https://toolbar.netcraft.com/site_report?url=https%3A%2F%2Fwww.qualcomm.com

Not being able to handle data securely, see: lhttps://www.eff.org/https-everywhere/atlas/domains/nr-data.net.html
this because of the tracker used by (insecure cookies are set for these hosts:) -bam.nr-data.net
(probably blocked by your adblocker inside your browser).

5 main privacy issues here: https://privacyscore.org/site/87163/
Retirable Symantec Class 3 Secure Server CA - G4 certificate (according to Google's).
-ss.symcb.com certified with a name and SAN mismatch, also vulnerable to Poodle exploit.

Info credits go to luntrus,

polonus (volunteer website security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!