[MlMt] Trouble connecting to iCloud (certificate validation)

Bill Cole mmlist-20120120 at billmail.scconsult.com
Tue Aug 18 17:20:56 EDT 2015


On 18 Aug 2015, at 16:48, Benny Kjær Nielsen wrote:

> Back to certificates. I've checked p01-p38 and they all provide the 
> same certificates and I wouldn't think there was a problem except for 
> the fact that I have an example from a user for which this is not 
> true. Connecting to `imap.mail.me.com` he got a certificate with this 
> issuer:
>
> 	Issuer: C=CZ, ST=Prague, O=AVAST, OU=Software Development, CN=Avast 
> trusted CA


That's because the user in question is unwisely using an Avast 
"security" suite that installs its own trusted root CA certificate and 
proceeds to hijack all SSL traffic and proxy it using bogus certificates 
signed by the Avast CA. This is a truly terrible behavioral model for 
supposed "security" software but it is common in commercial AV. That 
user has effectively handed full control of his computer and everything 
it does to the Avast snake oil hucksters.


More information about the mailmate mailing list