Live data from Hacker News

Lenovo Caught Installing Adware on New Computers

thenextweb.com

51–60 of 435 posts

Re: Lenovo Caught Installing Adware on New Computers

#51
post #5

This is much worse than just installing adware. They install a web proxy which MITMs all web connections, including HTTPS by means of a pre-installed trusted root certificate. The root certificate is the same across all installs, and the private key is present on the machine (necessarily, to operate the proxy): https://twitter.com/fugueish/status/568258997578371072 Someone will extract the private key in the next few…

I'm curious what legal stance Lenovo customers have here - their secure HTTPS connections are being MITMed intentionally - surely that's hacking, or some national security violation?

Re: Lenovo Caught Installing Adware on New Computers

#52
post #44

Just found this: Spy agencies ban Lenovo PCs on security concerns (27th July 2013) - http://www.afr.com/p/technology/spy_agencies_ban_lenovo_pcs_... "Multiple intelligence and defence sources in Britain and Australia confirmed there is a written ban on computers made by the Chinese company [Lenovo] being used in “classified” networks."

Another black eye if they knew about Superfish and didn't alert their citizens.

It is from 2013 though.

Re: Lenovo Caught Installing Adware on New Computers

#54
post #19

Earlier quoted context omitted.

Can't you just write all 0's to the drive or just reformat it? Genuine question here, why would you need to physically replace the drive to ensure security when you can write to the whole thing?

> with the cheapest drive offered and replacing the drive with an SSD I expect the "cheapest drive" is not an SSD.

hence "replacing the drive with an SSD"

Re: Lenovo Caught Installing Adware on New Computers

#55
post #12
post #5

This is much worse than just installing adware. They install a web proxy which MITMs all web connections, including HTTPS by means of a pre-installed trusted root certificate. The root certificate is the same across all installs, and the private key is present on the machine (necessarily, to operate the proxy): https://twitter.com/fugueish/status/568258997578371072 Someone will extract the private key in the next few…

Here's Lenovo trying to justify the presence of this software, naturally oblivious to the security implications: https://forums.lenovo.com/t5/Lenovo-P-Y-and-Z-series/Lenovo-...

naturally oblivious to the security implications

Rest assured Lenovo was perfectly aware of the security and privacy implications of this feature from the beginning.

They merely try to sound oblivious because their laywers hope that will soften the legal and media repercussions.

Re: Lenovo Caught Installing Adware on New Computers

#56

The article says that Superfish "injects third-party ads on Google searches." Does that include https://encrypted.google.com/ in Chrome and Firefox, or do key pinning and HSTS preloading successfully prevent that? EDIT: According to another comment here, HTTPS connections in Firefox aren't affected because they don't use the system certificate store. But what about Chrome - do users see an error on pages with pinned…

Locally added CAs override pinning, so no it wont help.

Re: Lenovo Caught Installing Adware on New Computers

#57
post #51
post #5

This is much worse than just installing adware. They install a web proxy which MITMs all web connections, including HTTPS by means of a pre-installed trusted root certificate. The root certificate is the same across all installs, and the private key is present on the machine (necessarily, to operate the proxy): https://twitter.com/fugueish/status/568258997578371072 Someone will extract the private key in the next few…

I'm curious what legal stance Lenovo customers have here - their secure HTTPS connections are being MITMed intentionally - surely that's hacking, or some national security violation?

It certainly seems like unauthorised use of a computer system, on the face of it.

Re: Lenovo Caught Installing Adware on New Computers

#58
post #31
post #13

This reinforces my policy of buying laptops with the cheapest drive offered and replacing the drive with an SSD before the first boot. I run Linux anyway, so booting Windows has no value for me.

You also have to reflash all firmware with known-trusted versions using a known-trusted reflasher to be safe. ... and replace the CPU with one that is known not to have backdoors. You'll have to craft it from Silicon yourself, though, because there aren't any available for sale anymore.

This is what it looks like when people don't recognize that security is a spectrum.

Re: Lenovo Caught Installing Adware on New Computers

#60
post #5

This is much worse than just installing adware. They install a web proxy which MITMs all web connections, including HTTPS by means of a pre-installed trusted root certificate. The root certificate is the same across all installs, and the private key is present on the machine (necessarily, to operate the proxy): https://twitter.com/fugueish/status/568258997578371072 Someone will extract the private key in the next few…

Mozilla discussion about what to do with the Superfish cert:

Bug 1134506 - Mark "Superfish, Inc." root certificate as untrusted in NSS

https://bugzilla.mozilla.org/show_bug.cgi?id=1134506

Post reply on HN