Avast is pioneer in HTTPS connection scanning

Parkinsond

Level 65
Thread author
Verified
Top Poster
Well-known
Dec 6, 2023
5,417
16,990
6,369
The HTTPS scanning method used by ESET and most other AV products (those who have this feature) involves the AV directly being a middleman between the web server and the browser, so the website's certificates are replaced by ESET's self-signing certificate.
The downside is we can not check the original certificate of the website. Browser makers hate this method as many of them call it security through obscurity.
Another downside is, it breaks security and privacy features like, Encrypted Client Hello.

Avast has been using a different method for many years. Instead of being a direct middleman, it relies on using the secret SSLKEYLOGFILE to reveal the contents of the secured HTTPS connection.

After Avast, now Kaspersky is also adopting this method. In the next version of Kaspersky, they are replacing the old method with the SSLKEYLOGFILE method. Currently in the testing phase, they are calling it, SuperMITM.

 
Indeed, Avast's method of HTTPS scanning is less intrusive and more privacy-friendly than the traditional middleman approach. It's good to see other antivirus software like Kaspersky adopting this method. It shows the pioneering role Avast has played in this area.
 
Hey that was me who posted this on the ESET forum.
Though Kaspersky was testing the alternate method in their beta version, according to @harlan4096 it wasn't pushed to the final stable build.
I don't know if it was permanently scrapped or they need more testing. I don't know if the next beta version is live or not but harlan would know.
 
Hey that was me who posted this on the ESET forum.
Though Kaspersky was testing the alternate method in their beta version, according to @harlan4096 it wasn't pushed to the final stable build.
I don't know if it was permanently scrapped or they need more testing. I don't know if the next beta version is live or not but harlan would know.
Indeed.
Apologies for not noticing the name; I was attracted by the explanation.
2025-07-19 20.29.26 forum.eset.com b8c2c5db4802.jpg
 
Using HTTPS scanning in any kind of security software is a huge NO-NO for me. Not only that it sees everything you do between you and the website, it slows down browsing speed, it also replaces website certificate with their own and in majority of cases breaks down encryption making you vulnerable hacking. Basically, you have to trust your antivirus software they aren't spying on you and don't have malicious intention with the data they have. Not to mention, you have to blindly trust them their SSL certificate is 100% safe.

And yes, all of antivirus companies will say how it's for better protection, how it's safe and that you shouldn't worry about it. But then, why none antivirus company discloses how the HTTPS scanning actually works and the consequences of having it enabled? I think we all know why.
 
Last edited:
Using HTTPS scanning in any kind of security software is a huge NO-NO for me. Not only that it sees everything you do between you and the website, it slows down browsing speed, it also replaces website certificate with their own and in majority of cases breaks down encryption making you vulnerable hacking. Basically, you have to trust your antivirus software they aren't spying on you and don't have malicious intention with the data they have. Not to mention, you have to blindly trust them their SSL certificate is 100% safe.

And yes, all of antivirus companies will say how it's for better protection, how it's safe and that you shouldn't worry about it. But then, why doesn't none disclose how the HTTPS scanning actually work and the consequences of having it enabled? I think we all know why.

And let alone some of the FP's they can produce. At one time BD forum was littered with Suspicious Connection blocked pop up threads and posts driving people nuts.
One of the reasons I like F-Secure, they don't use their own web certificate.
 
While was using K free (will miss those days), I usually disable encrypted connection scan, but install K extension which provided nearly equal web protection.
K extension is not necessary even in that scenario. All it does is, it enables Kaspersky to communicate with the browser in an efficient way. If the extension is not installed, then Kaspersky injects a script into every webpage (can be disabled in settings). If you have the extension, it doesn't need to inject the script. The extension otherwise has no security related purpose. For me the extension caused high CPU spike on some websites. So, when I used Kaspersky, I never used it.
 
K extension is not necessary even in that scenario. All it does is, it enables Kaspersky to communicate with the browser in an efficient way. If the extension is not installed, then Kaspersky injects a script into every webpage (can be disabled in settings). If you have the extension, it doesn't need to inject the script. The extension otherwise has no security related purpose. For me the extension caused high CPU spike on some websites. So, when I used Kaspersky, I never used it.
I have found disabling encrypted connection scan, with disabling script injection and not installing the extension leaves me almost without web protection.
 
I used to disable encrypted connection scan and the extension but kept the script injection feature.
I've never known what's the best to do with Kaspersky and this.

Saying that, it does look like they are changing how that all works. Although we've not heard anything in a while
 
  • Like
Reactions: rashmi
K extension is not necessary even in that scenario. All it does is, it enables Kaspersky to communicate with the browser in an efficient way. If the extension is not installed, then Kaspersky injects a script into every webpage (can be disabled in settings). If you have the extension, it doesn't need to inject the script. The extension otherwise has no security related purpose. For me the extension caused high CPU spike on some websites. So, when I used Kaspersky, I never used it.
I installed the extension and it still injected the script.
 
Using HTTPS scanning in any kind of security software is a huge NO-NO for me. Not only that it sees everything you do between you and the website, it slows down browsing speed, it also replaces website certificate with their own and in majority of cases breaks down encryption making you vulnerable hacking. Basically, you have to trust your antivirus software they aren't spying on you and don't have malicious intention with the data they have. Not to mention, you have to blindly trust them their SSL certificate is 100% safe.

And yes, all of antivirus companies will say how it's for better protection, how it's safe and that you shouldn't worry about it. But then, why none antivirus company discloses how the HTTPS scanning actually works and the consequences of having it enabled? I think we all know why.
The way I see it, you are already trusting the AV if you have it installed. If you don't trust the AV then don't install it in the first place. Https scanning has it's con but I think its pros outweigh it, at least for me. But I agree it does slow down webpage loading. You juggle pros and cons for everything in life.
 
A certificate MitM to enable HTTPS scanning defies basic best security practices because it is an inherent compromise of data exchange, but there are those here at MT that are batshit crazy about scanning every URL because "most threat actors have adopted HTTPS websites, compromised HTTPS sites, and HTTPS C&C."

There must be a lot of users out there with unhealthy paranoia about phishing and other malicious sites. They tend to be the ones that are high-risk users and know what they do routinely is unsafe (unrestricted grand tours of the internet and prolific downloading). Goes back to the first principle of most everting: "People are always the problem. ALWAYS."

While I disagree with those behaviors, users have the right to do whatever they want when it comes to use-of-system-self-control (or lack thereof) under the current global rules.
 
Last edited by a moderator:
A certificate MitM to enable HTTPS scanning defies basic best security practices because it is an inherent compromise of data exchange, but there are those here at MT that are batshit crazy about scanning every URL because "most threat actors have adopted HTTPS websites, compromised HTTPS sites, and HTTPS C&C."

There must be a lot of users out there with unhealthy paranoia about phishing and other malicious sites. They tend to be the ones that are high-risk users and know what they do routinely is unsafe (unrestricted grand tours of the internet and prolific downloading). Goes back to the first principle of most everting: "People are always the problem. ALWAYS."

While I disagree with those behaviors, users have the right to do whatever they want when it comes to use-of-system-self-control (or lack thereof) under the current global rules.
Avast-AVG accomplish without messing with the certificate.
 
  • Like
Reactions: rashmi
Using HTTPS scanning in any kind of security software is a huge NO-NO for me. Not only that it sees everything you do between you and the website, it slows down browsing speed, it also replaces website certificate with their own and in majority of cases breaks down encryption making you vulnerable hacking. Basically, you have to trust your antivirus software they aren't spying on you and don't have malicious intention with the data they have. Not to mention, you have to blindly trust them their SSL certificate is 100% safe.

And yes, all of antivirus companies will say how it's for better protection, how it's safe and that you shouldn't worry about it. But then, why none antivirus company discloses how the HTTPS scanning actually works and the consequences of having it enabled? I think we all know why.
I'm like you and want nothing to touch my connection or affect my browsing speed, not even 1$. Very few AVs have no HTTP scanning.

Panda Free Antivirus is one but I stopped using it because it messes up my browser cookies resetting them randomly so I have to spend hours relogging into each website.

You can do a custom install of Avast / AVG (any edition) and unselect HTTP scanning so it's not even there.

Those are the only options.
 
  • Like
Reactions: rashmi
I disable the HTTPS scanning feature in AVs. Besides the speed impact, HTTPS filtering is one reason I don't use AdGuard Desktop. If feasible, AdGuard could use its "Browser Assistant" to filter HTTPS websites and offer certificate installation (systemwide) or browser assistant choices for HTTPS filtering.

The extension otherwise has no security related purpose.
I believe the extension provides a "secure input" function for passwords and fields. I don't mean the virtual keyboard.

I installed the extension and it still injected the script.
I'm unsure, but I think the extension also injects a script.
 

You may also like...