<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Rays of Light&#187; Information Security</title>
	<atom:link href="http://raysoflight.trygstad.org/category/information-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://raysoflight.trygstad.org</link>
	<description>THE MUSINGS OF RAY TRYGSTAD: EDUCATOR, IT GUY, NAVAL OFFICER, WORLD TRAVELER &#38; PREACHER</description>
	<lastBuildDate>Sat, 28 Dec 2024 04:46:54 +0000</lastBuildDate>
	<language>en-US</language>
		<sy:updatePeriod>hourly</sy:updatePeriod>
		<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.7.1</generator>
	<item>
		<title>Hubris: Lenovo and Superfish</title>
		<link>http://raysoflight.trygstad.org/2015/02/24/hubris-lenovo-and-superfish/</link>
		<comments>http://raysoflight.trygstad.org/2015/02/24/hubris-lenovo-and-superfish/#comments</comments>
		<pubDate>Tue, 24 Feb 2015 00:59:33 +0000</pubDate>
		<dc:creator><![CDATA[Ray Trygstad]]></dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[ethics]]></category>
		<category><![CDATA[Lenovo]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Superfish]]></category>

		<guid isPermaLink="false">http://raysoflight.trygstad.org/?p=73</guid>
		<description><![CDATA[From one of my favorite blogs, Techdirt, here&#8217;s a concise breakout of the Lenovo/Superfish/Komodia affair that came out in the media last week: “Last week it came out that Lenovo was installing a bit of software called &#8220;Superfish&#8221; as a &#8230; <a class="more-link" href="http://raysoflight.trygstad.org/2015/02/24/hubris-lenovo-and-superfish/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>From one of my favorite blogs, <a title="Techdirt" href="https://www.techdirt.com/" target="_blank"><em>Techdirt</em></a>, here&#8217;s a concise breakout of the Lenovo/Superfish/Komodia affair that came out in the media last week:</p>
<blockquote><p><strong style="font-size: 200%; vertical-align: middle; line-height: 50%;">“</strong>Last week it came out that Lenovo was installing a bit of software called &#8220;Superfish&#8221; as a default bloatware on a bunch of its &#8220;consumer&#8221; laptops. The software tried to pop up useful alternative shopping results for images. But in order to work on HTTPS-encrypted sites, Superfish made use of a nasty (and horribly implemented) &#8220;SSL hijacker&#8221; from Komodia, which installed a self-signed root certificate that basically allowed anyone to issue totally fake security certificates for any encrypted connection, enabling very easy man-in-the-middle attacks. Among the many, many, many stupid things about the way Komodia worked, was that it used the same certificate on each installation of Superfish, and it had an easily cracked password: &#8220;komodia&#8221; which was true on apparently every product that used Komodia. And researchers have discovered that a whole bunch of products use Komodia, putting a ton of people at risk. People have discovered at least 12 products that make use of Komodia. <a title="Thought Komodia/Superfish Bug Was Really, Really Bad? It's Much, Much Worse!" href="https://www.techdirt.com/articles/20150223/07363930113/thought-komodiasuperfish-bug-was-really-really-bad-its-much-much-worse.shtml" target="_blank">(Read more&#8230;)</a><strong style="font-size: 200%; vertical-align: middle; line-height: 50%;">”</strong></p></blockquote>
<p>This is sort of the perfect storm at the intersection of ethics and cyber security, as it is behavior that has compromised/breached the security of Lenovo&#8217;s systems, and the two other companies involved refuse to even acknowledge that what they are doing is nothing short of a cybersecurity disaster, but from an ethical perspective, is just plain WRONG. It is an amazing demonstration of the kind of <a title="Hubris: excessive pride or self-confidence." href="https://en.wikipedia.org/wiki/Hubris" target="_blank">hubris</a> that we see in so many corporations today, complete with&#8221;ignore and deny&#8221; followed by &#8220;circle the wagons&#8221; and quickly descending to plain old fingerpointing. Only after being raked through the coals in the press did the lead player fess up and take responsibility, and the other players, the ones with the irredeemably broken business model, are still in the the deny everything and hope it will go away mode. Here&#8217;s how this went down in the trade AND popular press, in approximate chronological order&#8230;</p>
<p style="padding-left: 30px;"><a title="Lenovo Joins the Malevolent Side of the Online Advertising Industry" href="http://gizmodo.com/lenovo-joins-the-malevolent-side-of-the-online-advertis-1686922941" target="_blank">Lenovo Joins the Malevolent Side of the Online Advertising Industry</a> - <em>Gizmodo<br />
</em><a title="Lenovo’s Superfish nightmare is a sign that marketing tech has gone too far" href="http://venturebeat.com/2015/02/20/lenovos-superfish-nightmare-is-a-sign-that-marketing-tech-has-gone-too-far/" target="_blank">Lenovo’s Superfish nightmare is a sign that marketing tech has gone too far</a> &#8211; <em>Venturebeat VB News<br />
</em><a title="Lenovo CTO Admits It ‘Messed Up’ Allowing Major Security Hole Onto PCs" href="http://recode.net/2015/02/20/lenovo-cto-admits-it-messed-up-allowing-major-security-hole-onto-pcs/?utm_source=googleplay&amp;utm_medium=RSS&amp;utm_campaign=partnerfeed" target="_blank">Lenovo CTO Admits It ‘Messed Up’ Allowing Major Security Hole Onto PCs</a> - <em>re/code</em><br />
<a title="The biggest takeaway from 'Superfish': We need to push for &quot;No OS&quot; buying option." href="http://www.reddit.com/r/technology/comments/2wj6r1/the_biggest_takeaway_from_superfish_we_need_to/" target="_blank">The biggest takeaway from &#8216;Superfish&#8217;: We need to push for &#8220;No OS&#8221; buying option.</a>- <em>Reddit /r/technology<br />
</em><a title="Superfish admits installing root certificate authority to show ads on secure sites" href="http://thenextweb.com/insider/2015/02/21/superfish-admits-installing-root-certificate-authority-show-ads-secure-sites/" target="_blank">Superfish admits installing root certificate authority to show ads on secure sites</a> &#8211; <em>The Next Web</em><br />
<a title="Lenovo backpedals on Superfish adware, says it's working to 'restore trust'" href="http://mashable.com/2015/02/20/lenovo-apology-superfish/?utm_medium=feed&amp;utm_source=rss" target="_blank">Lenovo backpedals on Superfish adware, says it&#8217;s working to &#8216;restore trust&#8217;</a> -<em> Mashable<br />
</em><a title="Here’s How to Remove the Ghastly Superfish Adware From Lenovo Laptops" href="http://www.slate.com/blogs/future_tense/2015/02/20/how_to_remove_superfish_adware_from_lenovo_laptops.html" target="_blank">Here’s How to Remove the Ghastly Superfish Adware From Lenovo Laptops</a><span style="line-height: 1.4em;"> - </span><em style="line-height: 1.4em;">Slate</em><br />
<a title="How to remove the dangerous Superfish adware preinstalled on Lenovo PCs" href="http://www.pcworld.com/article/2886278/how-to-remove-the-dangerous-superfish-adware-presintalled-on-lenovo-pcs.html" target="_blank">How to remove the dangerous Superfish adware preinstalled on Lenovo PCs</a> -<em> PCWorld</em><br />
<a title="Lenovo CTO admits company 'messed up,' publishes Superfish removal tool" href="http://www.pcworld.com/article/2886690/lenovo-cto-admits-company-messed-up-and-will-publish-superfish-removal-tool-on-friday.html" target="_blank">Lenovo CTO admits company &#8216;messed up,&#8217; publishes Superfish removal tool </a>-<em> PCWorld<br />
</em><a title="Lenovo finally admits its sleazy adware ploy put its own customers at risk of being hacked" href="http://bgr.com/2015/02/20/lenovo-pc-adware-scandal-response/" target="_blank">Lenovo finally admits its sleazy adware ploy put its own customers at risk of being hacked</a><em> &#8211; BGR<br />
</em><a title="Lenovo's Superfish security snafu blows up in its face" href="http://www.cnet.com/news/superfish-torments-lenovo-owners-with-more-than-adware/" target="_blank">Lenovo&#8217;s Superfish security snafu blows up in its face</a> &#8211; <em>C|NET</em><br />
<a title="Here’s How To Get Rid Of That Nasty Superfish Vulnerability On Your New Lenovo Laptop" href="http://consumerist.com/2015/02/20/heres-how-to-get-rid-of-that-nasty-superfish-vulnerability-on-your-new-lenovo-laptop/" target="_blank">Here’s How To Get Rid Of That Nasty Superfish Vulnerability On Your New Lenovo Laptop</a> - <em>Consumerist<br />
</em><em></em><a title="Lenovo has just released an automatic Superfish removal tool" href="http://www.theverge.com/2015/2/20/8079933/lenovo-superfish-removal-tool-uninstall" target="_blank">Lenovo has just released an automatic Superfish removal tool</a> -<em> The Verge</em><br />
<a title="Bravo! Windows Defender, McAfee updates fully remove Lenovo's dangerous Superfish adware" href="http://www.pcworld.com/article/2886827/bravo-windows-defender-update-fully-removes-lenovos-dangerous-superfish-malware.html" target="_blank">Bravo! Windows Defender, McAfee updates fully remove Lenovo&#8217;s dangerous Superfish adware</a> &#8211; <em>PCWorld</em><br />
<a title="Lenovo Releases Tool To Remove The Sketchy Exploitable “SuperFish” Garbage It Pre-Loaded On Laptops" href="http://techcrunch.com/2015/02/20/how-to-remove-superfish-lenovo/" target="_blank">Lenovo Releases Tool To Remove The Sketchy Exploitable “SuperFish” Garbage It Pre-Loaded On Laptops</a> &#8211; <em>TechCrunch</em><br />
<a title="Microsoft has updated Windows Defender to root out the Superfish adware" href="http://www.theverge.com/2015/2/20/8077033/superfish-fix-microsoft-windows-defender" target="_blank">Microsoft has updated Windows Defender to root out the Superfish adware</a> - <em>The Verge</em><em></em><br />
<a title="Windows Defender destroys Superfish" href="http://www.slashgear.com/windows-defender-destroys-superfish-20369879/" target="_blank">Windows Defender destroys Superfish</a><em> &#8211; Slashgear<br />
</em><a title="Department of Homeland Security urges Lenovo users to remove Superfish" href="http://mashable.com/2015/02/20/department-homeland-security-superfish/" target="_blank">Department of Homeland Security urges Lenovo users to remove Superfish</a> - <em>Mashable</em><br />
<a title="U.S. Government Urges Lenovo Customers to Remove 'Superfish' Software" href="http://www.entrepreneur.com/article/243179" target="_blank">U.S. Government Urges Lenovo Customers to Remove &#8216;Superfish&#8217; Software</a> &#8211; <em>Entrepreneur</em><br />
<a title="US government urges Lenovo users to remove Superfish, but the software maker denies security risk" href="http://thenextweb.com/insider/2015/02/20/superfish-denies-its-software-poses-a-risk-as-the-us-government-warns-against-it/" target="_blank">US government urges Lenovo users to remove Superfish, but the software maker denies security risk</a> &#8211; <em>The Next Web</em><br />
<a title="CEO says Superfish is safe as US issues alert to remove Superfish from Lenovo PCs" href="http://www.pcworld.com/article/2887180/ceo-says-superfish-is-safe-as-us-issues-alert-to-remove-superfish-from-lenovo-pcs.html" target="_blank">CEO says Superfish is safe as US issues alert to remove Superfish from Lenovo PCs</a> &#8211; <em>PCWorld</em><br />
<a title="Lenovo CTO admits Superfish put users at risk, talks damage control" href="http://mashable.com/2015/02/20/lenovo-superfish-interview/" target="_blank">Lenovo CTO admits Superfish put users at risk, talks damage control</a> &#8211; <em>Mashable</em><br />
<a title="Lenovo slapped with lawsuit over dangerous Superfish adware" href="http://www.pcworld.com/article/2887392/lenovo-hit-with-lawsuit-over-superfish-snafu.html" target="_blank">Lenovo slapped with lawsuit over dangerous Superfish adware</a> &#8211; <em>PCWorld<br />
</em><strong>Or, just read the <a title="Superfish on Techdirt" href="https://www.techdirt.com/blog/?tag=superfish" target="_blank"><em>Techdirt</em> complete Superfish coverage</a></strong></p>
]]></content:encoded>
			<wfw:commentRss>http://raysoflight.trygstad.org/2015/02/24/hubris-lenovo-and-superfish/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Interviewed on WGN Chicago 9</title>
		<link>http://raysoflight.trygstad.org/2014/12/19/interviewed-on-wgn-chicago-9/</link>
		<comments>http://raysoflight.trygstad.org/2014/12/19/interviewed-on-wgn-chicago-9/#comments</comments>
		<pubDate>Fri, 19 Dec 2014 07:08:32 +0000</pubDate>
		<dc:creator><![CDATA[Ray Trygstad]]></dc:creator>
				<category><![CDATA[Information Security]]></category>

		<guid isPermaLink="false">http://raysoflight.trygstad.org/?p=68</guid>
		<description><![CDATA[Folks from WGN came to campus today and talked to me about the Sony hack. You can watch it on the top video at http://wgntv.com/2014/12/17/sony-will-not-release-the-interview-christmas-day/;  I come in at about 1:41 &#8230; <a class="more-link" href="http://raysoflight.trygstad.org/2014/12/19/interviewed-on-wgn-chicago-9/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p><img class="size-full wp-image-69 alignright" alt="WGN Interview 12-19-14" src="http://raysoflight.trygstad.org/wp-content/uploads/2014/12/WGN12-19-14.png" width="384" height="215" />Folks from WGN came to campus today and talked to me about the Sony hack. You can watch it on the top video at <a title="Ray talks about the Sony hack." href="http://wgntv.com/2014/12/17/sony-will-not-release-the-interview-christmas-day/" target="_blank">http://wgntv.com/2014/12/17/sony-will-not-release-the-interview-christmas-day/</a>;  I come in at about 1:41</p>
]]></content:encoded>
			<wfw:commentRss>http://raysoflight.trygstad.org/2014/12/19/interviewed-on-wgn-chicago-9/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Edward Snowden: Point/Counterpoint</title>
		<link>http://raysoflight.trygstad.org/2014/04/19/edward-snowden-pointcounterpoint/</link>
		<comments>http://raysoflight.trygstad.org/2014/04/19/edward-snowden-pointcounterpoint/#comments</comments>
		<pubDate>Fri, 18 Apr 2014 19:52:10 +0000</pubDate>
		<dc:creator><![CDATA[Ray Trygstad]]></dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[colleagues]]></category>
		<category><![CDATA[Infosec]]></category>
		<category><![CDATA[NSA]]></category>
		<category><![CDATA[Snowden]]></category>

		<guid isPermaLink="false">http://raysoflight.trygstad.org/?p=43</guid>
		<description><![CDATA[My friend and colleague Bill Slater did a presentation before an overflow crowd on Edward Snowden at IIT&#8217;s ForenSecure &#8217;14 conference this morning. In his truly excellent and well researched talk, Bill echoed some opinions of the NSA and members &#8230; <a class="more-link" href="http://raysoflight.trygstad.org/2014/04/19/edward-snowden-pointcounterpoint/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>My friend and colleague <a href="http://www.billslater.com/" target="_blank">Bill Slater</a> did a presentation before an overflow crowd on <a href="http://www.billslater.com/snowden/" target="_blank">Edward Snowden</a> at IIT&#8217;s <a href="http://forensecure.sat.iit.edu/" target="_blank">ForenSecure &#8217;14</a> conference this morning. In his truly excellent and well researched talk, Bill echoed some opinions of the NSA and members of the Congressional Intelligence Oversight Committees as to the &#8220;extreme dangers to national security&#8221; posed by Snowden&#8217;s disclosure&#8217;s about the NSA&#8217;s abuses. I felt compelled to offer a counterpoint to Bill&#8217;s position on some things in his presentation so I stood up and presented my view that Snowden is a <i>genuine</i> whistleblower who has cast a sharp and bright light on systemic and gross abuses of the <a href="http://en.wikipedia.org/wiki/Fourth_Amendment_to_the_United_States_Constitution" target="_blank">Fourth Amendment</a> by the NSA. I also pointed out that Snowden is only in Russia because he was in transit when the U.S. revoked his passport, and that all of the data in his possession was turned over to journalists before he left Hong Kong. Finally I discussed how seriously I take my oath to the Constitution, and how disgusted I am by those at the NSA who have taken the same and have abrogated that Oath so egregiously. It was a good session, a good discussion, and despite the appearance of dispute, Bill and I are still friends!</p>
]]></content:encoded>
			<wfw:commentRss>http://raysoflight.trygstad.org/2014/04/19/edward-snowden-pointcounterpoint/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
