Lenovo is still trying to control the damage caused by the "Superfishgate", but it was clear from the start that the computer manufacturer was not the only one installing software capable of emitting fake HTTPS certificates. Now, joining the blacklist are Lavasoft and Comodo, two companies that offer security applications. Lavasoft uses the same technology as Superfish in one of its products, and Comodo distributes a program with more serious effects.
We have often wondered how high-profile companies can make mistakes of this kind. Damaging user security for an extra bill can destroy a brand's reputation and affect its value overnight. Lenovo was the only company that escaped the decline in the PC market with solid and relatively inexpensive systems, but the preinstallation of Superfish on its systems has left a rather large stain on its record. As promised, Lenovo released an automatic tool that removes Superfish with a couple of clicks, and now they will have to wait for users to forget the bitter taste. The problem is that Superfish has exposed a nefarious practice, imitated by other companies that do not necessarily sell computers.
Two New Incriminated Companies
The first case is that of Lavasoft. Perhaps you remember that name thanks to its Ad-Aware program, which over time was quickly surpassed by much lighter and more efficient alternatives. Lavasoft offers its Ad-Aware Web Companion for free, a complement to traditional antivirus that protects the user's preferred web browser. In theory it sounds quite good, but Lavasoft decided to incorporate the SSL interception technology developed by Komodia, and which Superfish uses. On the other sidewalk appears Comodo PrivDog, an application that increases (in theory) user privacy. Although it does not use Komodia's code, what PrivDog does is even worse than Superfish, since it replaces every certificate with its own, even if the original certificate was invalid.
The Aftermath
Lavasoft and Comodo corrected both situations in their products, but it took a little exposure for the gears to start turning. This makes us think that the "Superfishgate" will be much longer than we imagined, and every piece of software related to certificates will probably end up under the microscope of experts.