Live data from Hacker News

Lenovo Caught Installing Adware on New Computers

thenextweb.com

11–20 of 435 posts

Re: Lenovo Caught Installing Adware on New Computers

#12
post #5

This is much worse than just installing adware. They install a web proxy which MITMs all web connections, including HTTPS by means of a pre-installed trusted root certificate. The root certificate is the same across all installs, and the private key is present on the machine (necessarily, to operate the proxy): https://twitter.com/fugueish/status/568258997578371072 Someone will extract the private key in the next few…

Here's Lenovo trying to justify the presence of this software, naturally oblivious to the security implications:

https://forums.lenovo.com/t5/Lenovo-P-Y-and-Z-series/Lenovo-...

Re: Lenovo Caught Installing Adware on New Computers

#14
post #5

This is much worse than just installing adware. They install a web proxy which MITMs all web connections, including HTTPS by means of a pre-installed trusted root certificate. The root certificate is the same across all installs, and the private key is present on the machine (necessarily, to operate the proxy): https://twitter.com/fugueish/status/568258997578371072 Someone will extract the private key in the next few…

Wow, there are tons of images on twitter about this [1]. There is one where they MITM https://www.bankofamerica.com/ too [2]. Why the hell would they do this. Brutal.

[1] https://twitter.com/search?q=%23superfish&src=typd

[2] https://twitter.com/kennwhite/status/568270748638318593/phot...

Re: Lenovo Caught Installing Adware on New Computers

#16
post #5

This is much worse than just installing adware. They install a web proxy which MITMs all web connections, including HTTPS by means of a pre-installed trusted root certificate. The root certificate is the same across all installs, and the private key is present on the machine (necessarily, to operate the proxy): https://twitter.com/fugueish/status/568258997578371072 Someone will extract the private key in the next few…

The certificate technique they use dates back to at least 2010 (possibly only in add-on form back then?) See https://groups.google.com/forum/m/#!topic/mozilla.support.fi... for example. This causes other problems too: http://www.id.ee/index.php?id=37046 It's not alone in this behavior: http://kb.mit.edu/confluence/display/istcontrib/Programs+tha...

Re: Lenovo Caught Installing Adware on New Computers

#19
post #13

This reinforces my policy of buying laptops with the cheapest drive offered and replacing the drive with an SSD before the first boot. I run Linux anyway, so booting Windows has no value for me.

Can't you just write all 0's to the drive or just reformat it? Genuine question here, why would you need to physically replace the drive to ensure security when you can write to the whole thing?
Post reply on HN