Live data from Hacker News

Lenovo Caught Installing Adware on New Computers

thenextweb.com

61–70 of 435 posts

Re: Lenovo Caught Installing Adware on New Computers

#61
post #32

I'm surprised that this is just now news. I received complaints from people participating in our beta trial ( http://sketchtogether.com ) from as early as October 22nd, 2014 that our website was broken, and it was because of Superfish being installed on their lenovo laptops. When they uninstalled Superfish, our webpage started working again. Superfish injected a line of code that referenced "sf_main.jsp" from a remot…

An all-new reason to use Content-Security-Policy. How much you want to bet that thing is XSSable?

>An all-new reason to use Content-Security-Policy

Correct me if I'm wrong, but I don't think any amount of CSP will help you in this situation. They're MITMing traffic and thus can modify the CSP headers.

Re: Lenovo Caught Installing Adware on New Computers

#62

Wow. I just bought my first Lenovo product recently, a Q190. I will not be purchasing anything from them again.

Yeah this is really disappointing. Lenovo had become my 'goto' recommendation for people looking for a laptop.

Sure as hell not going to be doing that any more.

Re: Lenovo Caught Installing Adware on New Computers

#63
post #5

This is much worse than just installing adware. They install a web proxy which MITMs all web connections, including HTTPS by means of a pre-installed trusted root certificate. The root certificate is the same across all installs, and the private key is present on the machine (necessarily, to operate the proxy): https://twitter.com/fugueish/status/568258997578371072 Someone will extract the private key in the next few…

Wow, there are tons of images on twitter about this [1]. There is one where they MITM https://www.bankofamerica.com/ too [2]. Why the hell would they do this. Brutal. [1] https://twitter.com/search?q=%23superfish&src=typd [2] https://twitter.com/kennwhite/status/568270748638318593/phot...

I assume it's easier to MITM everything.

Re: Lenovo Caught Installing Adware on New Computers

#64
post #28

Earlier quoted context omitted.

Would have to re-write/re-flash the firmware as well.

What is it that the firmware can achieve? Is the firmware capable hijacking data, communicating with the NIC and transmitting data? Or is it somehow injecting harmful code? I feel like I'm missing something here.

Ripped from yesterday's headlines ...

  ... rewrote the hard-drive firmware of infected computers—a
  never-before-seen engineering marvel that worked on 12 drive
  categories from manufacturers including Western Digital, Maxtor,
  Samsung, IBM, Micron, Toshiba, and Seagate.

  The malicious firmware created a secret storage vault that survived
  military-grade disk wiping and reformatting, making sensitive
  data stolen from victims available even after reformatting the
  drive and reinstalling the operating system. The firmware also
  provided programming interfaces that other code in Equation
  Group's sprawling malware library could access. Once a hard drive
  was compromised, the infection was impossible to detect or remove.
http://arstechnica.com/security/2015/02/how-omnipotent-hacke...

Re: Lenovo Caught Installing Adware on New Computers

#65
post #55
post #12

Earlier quoted context omitted.

Here's Lenovo trying to justify the presence of this software, naturally oblivious to the security implications: https://forums.lenovo.com/t5/Lenovo-P-Y-and-Z-series/Lenovo-...

naturally oblivious to the security implications Rest assured Lenovo was perfectly aware of the security and privacy implications of this feature from the beginning. They merely try to sound oblivious because their laywers hope that will soften the legal and media repercussions.

Honestly, I think that's unlikely. This is far too sloppy to have been intentional. There are much better ways to implement a backdoor when you control the OS image. This is just incompetence, plain and simple.

Superfish looks like the kind of crapware that pays OEMs to include it in their bundle. Lenovo took the cash and didn't bother to review the code. Superfish, for its part, probably doesn't have the best and brightest engineers working for them. They probably tasked a junior programmer with working around SSL, who then committed the first solution that worked without ever thinking about security implications, and they shipped it.

Re: Lenovo Caught Installing Adware on New Computers

#66
post #8
post #5

This is much worse than just installing adware. They install a web proxy which MITMs all web connections, including HTTPS by means of a pre-installed trusted root certificate. The root certificate is the same across all installs, and the private key is present on the machine (necessarily, to operate the proxy): https://twitter.com/fugueish/status/568258997578371072 Someone will extract the private key in the next few…

Anyway to see if that certificate is on a Lenovo computer? Anyway to remove it? I bought a Lenovo laptop recently, and I was appalled at the amount of crapware that was installed. It's a wonderful laptop at a great price, just too bad about the software.

> It's a wonderful laptop at a great price, just too bad about the software.

Lenovo's hardware support for Linux is great so unless there's something keeping you on Windows switching to a good Linux distro usually works fine on these laptops.

Re: Lenovo Caught Installing Adware on New Computers

#67
post #61
post #32

Earlier quoted context omitted.

An all-new reason to use Content-Security-Policy. How much you want to bet that thing is XSSable?

>An all-new reason to use Content-Security-Policy Correct me if I'm wrong, but I don't think any amount of CSP will help you in this situation. They're MITMing traffic and thus can modify the CSP headers.

Fair enough, though I'd bet they aren't smart enough to have actually blocked the header. They apparently don't even support WebSocket.

Re: Lenovo Caught Installing Adware on New Computers

#68

Just found this: Spy agencies ban Lenovo PCs on security concerns (27th July 2013) - http://www.afr.com/p/technology/spy_agencies_ban_lenovo_pcs_... "Multiple intelligence and defence sources in Britain and Australia confirmed there is a written ban on computers made by the Chinese company [Lenovo] being used in “classified” networks."

IIRC, that article is a fine combination of bullshit and technically correct. There is a "written ban" purchasing equipment from anyone not on the approved vendor list. Lenovo didn't ask to be on the list, they're not on the list, therefore they're banned. As am I. As are you.

Re: Lenovo Caught Installing Adware on New Computers

#69
post #5

This is much worse than just installing adware. They install a web proxy which MITMs all web connections, including HTTPS by means of a pre-installed trusted root certificate. The root certificate is the same across all installs, and the private key is present on the machine (necessarily, to operate the proxy): https://twitter.com/fugueish/status/568258997578371072 Someone will extract the private key in the next few…

Is there reason to believe that the same key is used on all machines?

Re: Lenovo Caught Installing Adware on New Computers

#70
Well, it seems as though this [superfish] is categorized as a virus on most websites. From their own description:

"Superfish Window Shopper is a free browser add-on that instantly compares prices and shows similar items on ANY product in hundreds of U.S. online stores including Amazon.com, Best Buy, Macys, Nordstorm, Overstock.com, Staples, Target, and Wal-mart."

So if I have this right, this is essentially a massive affiliate scheme to produce revenue for the company? If it compares prices on all these sites, affid='s are injected for Lenovo and a % of the sale is given to them?

Edit: doing the math here on this for the last few hours and even if just a few million units have been sold, this has to be 10's of millions in dollars (being very generous) over the past few quarters.

There reviews are horrible as well. All spam / annoyance related.

Post reply on HN