TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Savitech USB audio drivers install a new root CA certificate

406 pointsby finnnover 7 years ago

17 comments

ryan-cover 7 years ago
The &quot;Universal ADB Driver&quot; for Android devices[1] also installs a root CA, however it instead generates the CA during install, signs the driver, deletes the private key, then installs the CA and driver.<p>1. <a href="https:&#x2F;&#x2F;github.com&#x2F;koush&#x2F;UniversalAdbDriver" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;koush&#x2F;UniversalAdbDriver</a>
评论 #15614595 未加载
评论 #15614591 未加载
userbinatorover 7 years ago
I am not saddened by this event, but by the fact that such occurrences will only add momentum to the movement to lock down computing devices and take freedom away from their users:<p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=12061320" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=12061320</a><p>Those worrying about security should remember that device drivers already run in ring 0 and can do anything they damn well please.<p>Thus I say: Good on Savitech for not being afraid to rebel against; and fuckings to the corporatocracy that is certificate authorities and the authoritarian security industry.
评论 #15617423 未加载
评论 #15617893 未加载
评论 #15618579 未加载
评论 #15619425 未加载
评论 #15616205 未加载
评论 #15618449 未加载
Osirisover 7 years ago
Why does Windows allow programs to install root CA certs without separate user intervention (beyond the initial &quot;grant admin permissions&quot; dialog)?
评论 #15614800 未加载
评论 #15614779 未加载
评论 #15615104 未加载
walrus01over 7 years ago
I would honestly be more worried about the root CAs which are enabled by default in the most popular OSes and browsers, with root CA privileges for government of China controlled entities, Turkish government entities and unethical&#x2F;shoddy root CAs such as Symantec. The Netherlands recently passed a law allowing the government specifically to use false keys and run MITM on crypto, which brings into question all .NL based CAs.
评论 #15615084 未加载
评论 #15616648 未加载
评论 #15614791 未加载
brian-armstrongover 7 years ago
So this is a CFAA violation, right? When will we finally hold someone accountable for blatant security issues like this?
评论 #15614291 未加载
评论 #15614717 未加载
评论 #15614247 未加载
joostersover 7 years ago
It seems unacceptable to me that the updated drivers do not automatically uninstall the CA. How is an ordinary user meant to navigate the certificate store and delete the CA?
edejongover 7 years ago
Phrased differently: operating system Microsoft Windows allows silent installation of Root Certificate during installation of unrelated USB driver installation, despite featuring a micro-kernel design.
elbigbadover 7 years ago
Can someone explain root certificates to me and why this is an issue? I know they sign certificates with a private key at a high level, but don&#x27;t get the implications of that generally.
评论 #15615345 未加载
评论 #15615334 未加载
grandalfover 7 years ago
Is there software that will check the certs on my computers to make sure no software has done this?
评论 #15614692 未加载
评论 #15614742 未加载
drzaiusapelordover 7 years ago
&gt;Microsoft provides guidance on deleting and managing certificates in the Windows certificate store<p>Microsoft should mark these as malicious and quarantine them using their built-in AV. If the end user needs them he can remove them from quarantine. Posting advisories no end user will ever see isn&#x27;t helping much.
revelationover 7 years ago
The only version of Windows XP that enforces driver signing is the unicorn 64 bit one, surely they didn&#x27;t develop the driver for that?<p>And what kind of odds do I get on the certs having a EKU for anything but driver signing?
ArchReaperover 7 years ago
Why are they allowed to bundle malware in their drivers? Why is this not illegal?
评论 #15614767 未加载
xstartupover 7 years ago
Alright, so if we get tons of install of our root CA cert. Can we start a new CA?
评论 #15614372 未加载
评论 #15614394 未加载
pfarnsworthover 7 years ago
Is there a list of trusted CA certs that we could use to scan to see if we have any that may not be trusted?
评论 #15615640 未加载
obituary_latteover 7 years ago
Curious as to why EMC got notified 20 days before anyone else...
arca_voragoover 7 years ago
One more reason to add to the innumerable list of why not to use windows.
评论 #15615599 未加载
fiatjafover 7 years ago
This, and all other thousands of cases of malware in the universe should mean something for those who defend &quot;native&quot; apps over webapps.
评论 #15615091 未加载