Kaspersky and MalwareTips

Kaspersky
31 Replies 4,124 Views

Parkinsond

Level 68
Verified
Top Poster
Well-known
When choosing "always scan encrypted connections" in Kaspersky, it inserts its personal root certificate for all sites, including Facebook, X, Google, Vodafone, Outlook, ect

Only MalwareTips forum withstand its certificate 💪💪💪

Capture.PNG
 
MalwareTips certificate whitelisted, while certificate of Facebook and X are not?!
Facebook and X are more likely to have malicious contents than MalwareTips so it's not surprising that Kaspersky do HTTPS filtering on those sites. Websites do not withstand these things. It's between browsers and the AV's HTTPS scanning component.
Since @harlan4096 sees Kaspersky certificate on MalwareTips, both of you can try logging out of MalwareTips, clean cookies for MalwareTips, delete cache and then reopen the browser and visit the site again. I know harlan uses Firefox and you are using Edge. Maybe harlan can do the above and check what he sees on Edge.
 
Facebook and X are more likely to have malicious contents than MalwareTips so it's not surprising that Kaspersky do HTTPS filtering on those sites. Websites do not withstand these things. It's between browsers and the AV's HTTPS scanning component.
Since @harlan4096 sees Kaspersky certificate on MalwareTips, both of you can try logging out of MalwareTips, clean cookies for MalwareTips, delete cache and then reopen the browser and visit the site again. I know harlan uses Firefox and you are using Edge. Maybe harlan can do the above and check what he sees on Edge.
Apart from Facebook and X, every single website had Kaspersky certificate, including trusted domains like Google, Microsoft, Vodafone, ChatGPT, and more.
Also, all forums like MalwareTips had the certificate.
I doube cleaning cookies and cache might help; other forums had the certificate even when I am logged in.
 
I've cheked on my system using ESET, since they also use their cerificate for MITM and also found out that MalwareTips website's certificate is not replaced by Eset's. I also disabled option "Do not scan traffic by domains trusted by ESET" but it made no difference.
Though on my system there are some other sites that do not get their ceritifacate replaced next to MalwareTips. Something I found in common for them is that they all use certificates issued by Google Trust Services and use root certificate GTS Root R4.
So it seems that Eset whitelists those certificate for some reason.
Kaspersky probably also whitelists some of them but they use different whitelist.
 
I've cheked on my system using ESET, since they also use their cerificate for MITM and also found out that MalwareTips website's certificate is not replaced by Eset's. I also disabled option "Do not scan traffic by domains trusted by ESET" but it made no difference.
Though on my system there are some other sites that do not get their ceritifacate replaced next to MalwareTips. Something I found in common for them is that they all use certificates issued by Google Trust Services and use root certificate GTS Root R4.
So it seems that Eset whitelists those certificate for some reason.
Kaspersky probably also whitelists some of them but they use different whitelist.
But selecting to scan all encrypted should disregard the original certificate however it is trusted!
 
But selecting to scan all encrypted should disregard the original certificate however it is trusted!
Yes I agree. IMO there is either a bug in ESET's handling of those certificates or they just use some whitelist that can't be dissabled.
I even put SSL scanning in interactive mode (so that I get question for each certificate) and also manually created rules for domain, but scanning is just not performed (similar on some other sites: youtube, gmail...).
Maybe I'lll look into it later when I'll have more time.
 
Apart from Facebook and X, every single website had Kaspersky certificate, including trusted domains like Google, Microsoft, Vodafone, ChatGPT, and more.
Also, all forums like MalwareTips had the certificate.
I doube cleaning cookies and cache might help; other forums had the certificate even when I am logged in.
Allowing any party to insert a certificate to Man-in-the-Middle your encrypted communications sessions is just plain stupid. It is stupid to trust Kaspersky or any other AV that uses a root certificate to MitM HTTPS or any other type of encrypted session.

It is very difficult to understand how so many people think it is a good thing. The ignorant ones that don't know any better, well, they're just ignorant. The ones that consciously allow any software to do it are not very smart nor wise.
 
Allowing any party to insert a certificate to Man-in-the-Middle your encrypted communications sessions is just plain stupid. It is stupid to trust Kaspersky or any other AV that uses a root certificate to MitM HTTPS or any other type of encrypted session.

It is very difficult to understand how so many people think it is a good thing. The ignorant ones that don't know any better, well, they're just ignorant. The ones that consciously allow any software to do it are not very smart nor wise.
This problem has been discussed by several browser vendors. I don't think it is healthy to insert a certificate either. It's all bullshit. AV vendors have gone in a direction that is no longer healthy. Plus, they unnecessarily slow down the browsing experience.

What then is worth using for home users?
 
Something I found in common for them is that they all use certificates issued by Google Trust Services and use root certificate GTS Root R4.
This is correct and this is something Bitdefender also do. Even in some pirated sports streaming sites that I often visit are not SSL scanned because of this reason.
BTW, ESET does HTTPS scanning on MalwareTips for me on MS Edge but doesn't do on Firefox.
For Edge, if I clean cookies, cache, reopen the browser and visit MT then on first visit HTTPS scanning is not performed but for all subsequent visits there is always ESET's certificate on Edge. This exact behavior at least on Edge is not new. I have been seeing this for many years.
On Firefox the QUIC version of MT is loaded while on Edge it's TLS 1.3 (excluding first visit). In Chromium browsers, using self-signing certificate to filter QUIC traffic is not allowed yet, so it has to be either forced to load TLS 1.3 or no HTTPS scanning on the site. On Firefox, filtering QUIC with self-signing certificate is allowed. Maybe this is where the difference is coming from. But I can't tell for sure why.
Kaspersky cannot filter QUIC at all, so they force downgrade everything to TLS 1.3 on all browsers.
 
Last edited:
This is correct and this is something Bitdefender also do. Even in some pirated sports streaming sites that I often visit are not SSL scanned because of this reason.
BTW, ESET does HTTPS scanning on MalwareTips for me on MS Edge but doesn't do on Firefox.
For Edge, if I clean cookies, cache, reopen the browser and visit MT then on first visit HTTPS scanning is not performed but for all subsequent visits there is always ESET's certificate on Edge. This exact behavior at least on Edge is not new. I have been seeing this for many years.
On Firefox the QUIC version of MT is loaded while on Edge it's TLS 1.3 (excluding first visit). In Chromium browsers, using self-signing certificate to filter QUIC traffic is not allowed yet, so it has to be either forced to load TLS 1.3 or no HTTPS scanning on the site. On Firefox, filtering QUIC with self-signing certificate is allowed. Maybe this is where the difference is coming from. But I can't tell for sure why.
Kaspersky cannot filter QUIC at all, so they force downgrade everything to TLS 1.3 on all browsers.
Exactly another reason i dropped Bitdefender. Still very happy with TM ;-)
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top