This is much worse than just installing adware. They install a web proxy which MITMs all web connections, including HTTPS by means of a pre-installed trusted root certificate. The root certificate is the same across all installs, and the private key is present on the machine (necessarily, to operate the proxy): https://twitter.com/fugueish/status/568258997578371072 Someone will extract the private key in the next few…
Lenovo Caught Installing Adware on New Computers
51–60 of 435 posts
Re: Lenovo Caught Installing Adware on New Computers
#52Just found this: Spy agencies ban Lenovo PCs on security concerns (27th July 2013) - http://www.afr.com/p/technology/spy_agencies_ban_lenovo_pcs_... "Multiple intelligence and defence sources in Britain and Australia confirmed there is a written ban on computers made by the Chinese company [Lenovo] being used in “classified” networks."
Another black eye if they knew about Superfish and didn't alert their citizens.
Re: Lenovo Caught Installing Adware on New Computers
#53Re: Lenovo Caught Installing Adware on New Computers
#54Earlier quoted context omitted.
Can't you just write all 0's to the drive or just reformat it? Genuine question here, why would you need to physically replace the drive to ensure security when you can write to the whole thing?
> with the cheapest drive offered and replacing the drive with an SSD I expect the "cheapest drive" is not an SSD.
Re: Lenovo Caught Installing Adware on New Computers
#55This is much worse than just installing adware. They install a web proxy which MITMs all web connections, including HTTPS by means of a pre-installed trusted root certificate. The root certificate is the same across all installs, and the private key is present on the machine (necessarily, to operate the proxy): https://twitter.com/fugueish/status/568258997578371072 Someone will extract the private key in the next few…
Here's Lenovo trying to justify the presence of this software, naturally oblivious to the security implications: https://forums.lenovo.com/t5/Lenovo-P-Y-and-Z-series/Lenovo-...
Rest assured Lenovo was perfectly aware of the security and privacy implications of this feature from the beginning.
They merely try to sound oblivious because their laywers hope that will soften the legal and media repercussions.
Re: Lenovo Caught Installing Adware on New Computers
#56The article says that Superfish "injects third-party ads on Google searches." Does that include https://encrypted.google.com/ in Chrome and Firefox, or do key pinning and HSTS preloading successfully prevent that? EDIT: According to another comment here, HTTPS connections in Firefox aren't affected because they don't use the system certificate store. But what about Chrome - do users see an error on pages with pinned…
Re: Lenovo Caught Installing Adware on New Computers
#57This is much worse than just installing adware. They install a web proxy which MITMs all web connections, including HTTPS by means of a pre-installed trusted root certificate. The root certificate is the same across all installs, and the private key is present on the machine (necessarily, to operate the proxy): https://twitter.com/fugueish/status/568258997578371072 Someone will extract the private key in the next few…
I'm curious what legal stance Lenovo customers have here - their secure HTTPS connections are being MITMed intentionally - surely that's hacking, or some national security violation?
Re: Lenovo Caught Installing Adware on New Computers
#58This reinforces my policy of buying laptops with the cheapest drive offered and replacing the drive with an SSD before the first boot. I run Linux anyway, so booting Windows has no value for me.
You also have to reflash all firmware with known-trusted versions using a known-trusted reflasher to be safe. ... and replace the CPU with one that is known not to have backdoors. You'll have to craft it from Silicon yourself, though, because there aren't any available for sale anymore.
Re: Lenovo Caught Installing Adware on New Computers
#59Wow. I just bought my first Lenovo product recently, a Q190. I will not be purchasing anything from them again.
Re: Lenovo Caught Installing Adware on New Computers
#60This is much worse than just installing adware. They install a web proxy which MITMs all web connections, including HTTPS by means of a pre-installed trusted root certificate. The root certificate is the same across all installs, and the private key is present on the machine (necessarily, to operate the proxy): https://twitter.com/fugueish/status/568258997578371072 Someone will extract the private key in the next few…
Bug 1134506 - Mark "Superfish, Inc." root certificate as untrusted in NSS