Evidence was found indicating that cybercriminals may be using Komodia software, which is embedded in Superfish for attacks.
Last week, the Superfish browser add-on that came pre-installed on some Lenovo laptop models sparked a security debate among researchers, considering the fact that it added an auto-signed certificate for validating HTTPS websites, with the same RSA private key on all machines.
The software is inserted between the client and the server and acts as a proxy for both parties, for decrypting the traffic.
Having knowledge of the Crypto key (Robert Graham discovered it in three hours), an attacker could intervene in the secure communication from the victim's machine to a server.
Security researchers from the Electronic Frontier Foundation (EFF) discovered more than 1,600 cases where Komodia's software failed to reject invalid certificates from HTTPS websites.
The problem is deeper than that, however, because Komodia re-signs an invalid certificate (making it valid), but changes the website's name in order to trigger a warning in the web browser.
However, the certificate itself can be used to validate multiple websites by adding the domain name to a field called Subject Alternative Name.
Cloudflare 's Filippo Valsorda found that Komodia leaves this information intact. This means that the certificate is valid for other domains and the browser only issues a warning in the case of the primary one.
Joseph Bonneau and Jeremy Gillula of the EFF reported in a blog post on Wednesday that data from the Decentralized SSL Observatory revealed high-profile domains affected including Google, Yahoo, Amazon, Bing, eBay, Twitter, Netflix, GPG4Win.org, several banking websites, and the Mozilla Add-Ons website.
“It is likely that Komodia's software allowed real MitM attacks that gave attackers access to users' email, search history, social media accounts, e‑commerce accounts, bank accounts, and even the ability to install malicious software that can compromise a user's browser or read their encryption keys”, the researchers added.
Komodia licenses its software with SSL Digestor and has included it in several pieces of software, in addition to Superfish, which is used to place ads on websites. It is also used in parental control applications such as Qustodio, Kurupira WebFilter or Komodia's Keep My Family Secure.
