Author Topic: Comodo ships Adware Privdog worse than Superfish  (Read 12039 times)

0 Members and 1 Guest are viewing this topic.

Offline Rednose

  • Pirate Party Member
  • Avast Überevangelist
  • Massive Poster
  • *****
  • Posts: 3739
  • Bits of Freedom : https://www.bof.nl
    • Nederlandstalig Avast! forum
Comodo ships Adware Privdog worse than Superfish
« on: February 23, 2015, 01:02:22 PM »
There is an adware called Privdog that gets shipped with software from Comodo. It totally breaks HTTPS security.

https://blog.hboeck.de/archives/865-Comodo-ships-Adware-Privdog-worse-than-Superfish.html

Greetz, Red.
« Last Edit: February 23, 2015, 01:08:30 PM by Rednose »
OS: Win 10 / iOS 17 / Debian 12 / Tails 5
Real Time: Avast Premium Security
On Demand: Malwarebytes
VPN: NordVPN ( NordLynx ) with Threat Protection ( Lite )

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: Comodo ships Adware Privdog worse than Superfish
« Reply #1 on: February 23, 2015, 02:08:47 PM »
Hi Rednose,

Thanks for reporting. As I said here in the forums earlier this Superfish drama will only be the tip of an iceberg. All try to trick us into these MIM attacks that breaks fundamental privacy security and it goes on and on. HTTPS has been downgraded, backdoored and is pn*wned big time, thanks to big commerce and various government services.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Re: Comodo ships Adware Privdog worse than Superfish
« Reply #2 on: February 23, 2015, 04:15:26 PM »
Comodo owns PrivDog. Caution...always use the custom install if available.
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89062
  • No support PMs thanks
Re: Comodo ships Adware Privdog worse than Superfish
« Reply #3 on: February 23, 2015, 04:32:27 PM »
There is an adware called Privdog that gets shipped with software from Comodo. It totally breaks HTTPS security.

https://blog.hboeck.de/archives/865-Comodo-ships-Adware-Privdog-worse-than-Superfish.html

Greetz, Red.

Great - NOT.

Considering that Comodo is also a Security Certificate Issuing Authority - this really is a huge no, no.

Again another huge trust issue and worse still from a company that issues security certificates, exactly a big point being made in the above article.

For those with a long memory they will probably remember Comodo's Certificate Issuing Authority having another fail with a number of certificates having to be blacklisted or banned, etc..
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: Comodo ships Adware Privdog worse than Superfish
« Reply #4 on: February 23, 2015, 05:05:02 PM »
Hi DavidR and Rednose,

The risks are there with us to stay:
Quote
SSL/TLS traffic now comprises 15-25% of total web traffic. While SSL/TLS provides privacy and authentication, cybercriminals can use SSL to hide their exploits from an organisation’s security controls by hiding attacks, evading detection, and bypassing critical security controls.

Most organisations lack the ability to inspect and decrypt SSL communications to detect these threats. This undermines traditional layered defenses and creates an unacceptable risk of breach and data loss.

As I said Superfish and PrivDog just the tip of the iceberg  that SSL Titanic, huge but vulnerable, has struck....  ;D

Interesting article: https://theoverspill.wordpress.com/2015/02/20/start-up-lenovo-superfish-and-its-implications-identifying-jackson-pollocks-tech-v-fashion-and-more/   article author = Charles Arthur

Everybody now seems woken up about this Adtrustmedia PrivDog injection scam: http://www.kb.cert.org/vuls/id/366544

polonus
« Last Edit: February 23, 2015, 05:42:18 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: Comodo ships Adware Privdog worse than Superfish
« Reply #5 on: February 23, 2015, 05:44:47 PM »
Privdog is Superfish all over again
http://www.ghacks.net/2015/02/23/privdog-is-superfish-all-over-again/

Quote
In case you are wondering what the connection between Comodo and PrivDog is: the CEO and founder of Comodo seems to be behind Privdog as well.


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: Comodo ships Adware Privdog worse than Superfish
« Reply #6 on: February 23, 2015, 06:13:35 PM »
Hi Pondus,

So we all are gonna test here: https://www.ssllabs.com/ssltest/viewMyClient.html
You only can see whther there is a proxy service running.

polonus

Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Online bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48567
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Comodo ships Adware Privdog worse than Superfish
« Reply #7 on: February 23, 2015, 06:17:51 PM »
I always knew there was a reason to avoid the Comodo Dragon.
It just took a while for everyone else to find out I made the right choice. :)
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89062
  • No support PMs thanks
Re: Comodo ships Adware Privdog worse than Superfish
« Reply #8 on: February 23, 2015, 06:20:43 PM »
Well you know me and tests - they can't run unless I allow them.

I can only assume what they report is based on the standard headed information browser, OS etc.

If I do allow ssllabs.com, relatively clean bill of health.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: Comodo ships Adware Privdog worse than Superfish
« Reply #9 on: February 23, 2015, 06:28:03 PM »
Hi bob3160, others  had short memories, those Comodo warans were caught red-handed last time. They did not learn anything, while  proceeding in the same way and they were only concerned how long they could do this unnoticed, and if not found out they would have continued the scheme. Apparently all have short memories here and do not take any consequences from what happens. We had the DigiNotar scandal, we had BEAST, we had POODLE, lenovo, now PrivDog and not a lot of users, like you, bob3160, discontinued their services. Keep it off of your comp and they will learn the hard way. Just as with ABP, found out uBlock is better. So out went ABP.
Bad reputation, with me it is only once, and they won't get another chance to play such a trick again, easy enough..

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Online bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48567
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
« Last Edit: February 23, 2015, 06:51:13 PM by bob3160 »
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: Comodo ships Adware Privdog worse than Superfish
« Reply #11 on: February 23, 2015, 09:55:33 PM »
Hi bob3160,

And that is what I like about you, bob3160, somewhere you will draw a line and they won't cross that line again.
That is what I learned from you and it brought respect. Thanks, bob3160,
"In God we trust, rest we test".

Damian
« Last Edit: February 23, 2015, 10:10:48 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: Comodo ships Adware Privdog worse than Superfish
« Reply #12 on: February 24, 2015, 01:28:38 PM »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: Comodo ships Adware Privdog worse than Superfish - now even more hijackers!
« Reply #13 on: February 26, 2015, 02:58:33 PM »
Update - the Superfish, PrivDog etc. scandal is spreading. I told you all this could be the proverbial tip of the iceberg detected, and it seems however true - much more parties were (are) into the same despicable schemes, so cybercriminals can hop onto the this band-waggon of Browser Hijacking as well:
http://www.howtogeek.com/210265/download.com-and-others-bundle-superfish-style-https-breaking-adware/
and two of the top ten downloads on CNET (KMPlayer and YTD) are bundling two different types of HTTPS-hijacking adware,

polonus
« Last Edit: February 26, 2015, 03:01:44 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Re: Comodo ships Adware Privdog worse than Superfish
« Reply #14 on: February 26, 2015, 04:26:45 PM »
OT, but that is why I don't like to download anything from cnet.com unless I absolutely have to.
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.