HomeSecurityKaspersky fixes bug affecting 400 million users

Kaspersky fixes bug affecting 400 million users

Kaspersky has fixed a certificate validation bug in its software that affected 400 million users.

It was discovered by Google's persistent bug-hunter Tavis Ormandy. The flaw lies in how the company's antivirus inspects encrypted traffic.Kaspersky

Since it decrypts the traffic before inspection, Kaspersky presents its certificates as a trusted authority. If a user opens Google in their browser, for example, the certificate will appear to come from Kaspersky Anti-Virus Personal Root.

The problem Ormandy identified is that the internal certificates were incredibly weak.

“As new certificates and keys are generated, they are entered using the first 32 bits of 3MD5(serialNumber||issuer) as the key… You don’t have to be a cryptographer to understand that a 32-bit key is not enough to prevent brute-force attacks,” the researcher says.

For the bug report Ormandy provided a PoC of a certificate conflict between Hacker News and manchesterct.gov:

“If you’re using Kaspersky Antivirus in Manchester, and you’re wondering why Hacker News sometimes doesn’t work, it’s because a critical vulnerability disabled SSL certificate validation for 400 million Kaspersky users.”

Kaspersky reportedly patched the bug on December 28.

Kaspersky: SSL interception differentiates certificates with a 32bit hash

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS