The security certificate – an encryption key – used by the Superfish add-on installed on Lenovo computers has just been cracked.We
recently reported that the Superfish software used by Lenovo generates a security certificate to re-sign all security certificates it receives from HTTPS pages, such as banking pages, essentially allowing access to plaintext information in traffic between client and server that would otherwise be encrypted.
Multiple security experts who looked into the matter revealed that the add-on uses the same RSA key (1024 bits) across all devices, meaning that if someone manages to crack it, they would be able to “read” the encrypted traffic exchanged between a Lenovo user and a secure service. That’s exactly what Robert Graham, CEO of Errata Security, did.
The researcher used a system with Superfish installed by dumping the data generated by the processes into the system's memory.
After discovering the encrypted private key of the security certificate used by Superfish, and the certificate itself, he tried to verify that the data was protected with a password.
Cracking the password turned out to be a bit more difficult than expected, since it required a modified brute-force program. When Graham had to develop new brute-force software for the needs of this attack.
He assumed the password wouldn’t be complex, so he instructed the program to search only among lowercase letters. In less than 10 seconds, it discovered the password, which was “komodia.”
The password decrypts the root certificate and could be used in man-in-the-middle attacks against Lenovo users who have Superfish installed on their system.

Source: secnews.gr
