Lenovo Caught Installing Adware on New Computers
71–80 of 435 posts
Re: Lenovo Caught Installing Adware on New Computers
#72This is much worse than just installing adware. They install a web proxy which MITMs all web connections, including HTTPS by means of a pre-installed trusted root certificate. The root certificate is the same across all installs, and the private key is present on the machine (necessarily, to operate the proxy): https://twitter.com/fugueish/status/568258997578371072 Someone will extract the private key in the next few…
I'm curious what legal stance Lenovo customers have here - their secure HTTPS connections are being MITMed intentionally - surely that's hacking, or some national security violation?
Re: Lenovo Caught Installing Adware on New Computers
#73Re: Lenovo Caught Installing Adware on New Computers
#74This reinforces my policy of buying laptops with the cheapest drive offered and replacing the drive with an SSD before the first boot. I run Linux anyway, so booting Windows has no value for me.
Re: Lenovo Caught Installing Adware on New Computers
#75Earlier quoted context omitted.
naturally oblivious to the security implications Rest assured Lenovo was perfectly aware of the security and privacy implications of this feature from the beginning. They merely try to sound oblivious because their laywers hope that will soften the legal and media repercussions.
Honestly, I think that's unlikely. This is far too sloppy to have been intentional. There are much better ways to implement a backdoor when you control the OS image. This is just incompetence, plain and simple. Superfish looks like the kind of crapware that pays OEMs to include it in their bundle. Lenovo took the cash and didn't bother to review the code. Superfish, for its part, probably doesn't have the best and br…
Re: Lenovo Caught Installing Adware on New Computers
#76I even considered buying a Lenovo recently when a pretty nice looking ThinkPad was on sale, but a couple of friends have had very bad experiences with their Lenovo laptops. Both have had to go back to Lenovo for repairs; one of them had to send it back twice, and on the second go around demanded a new one instead of a repaired one, because the "repaired" one was worse than when it went in for repairs.
That said, there's "bad QC", which is forgivable with time and a sincere effort by the company to correct it, and then there's "evil". Intentionally shipping adware is evil.
Given this, I can genuinely think of no way for Lenovo to ever get my business for any product.
Re: Lenovo Caught Installing Adware on New Computers
#77Lenovo was the last respected PC laptop brand. Is there anyone I can trust to sell me a well-made laptop anymore besides Apple?
Re: Lenovo Caught Installing Adware on New Computers
#78http://i.imgur.com/7cFlZLr.png
http://i.imgur.com/R4sHowP.png
So on a fresh Windows 7 virtual machine with zero apps installed, this program gives me 200 some errors and wants $49.99 (-$20 for instant savings) to register the program. This keeps getting better. Typical scam.
Re: Lenovo Caught Installing Adware on New Computers
#79This is much worse than just installing adware. They install a web proxy which MITMs all web connections, including HTTPS by means of a pre-installed trusted root certificate. The root certificate is the same across all installs, and the private key is present on the machine (necessarily, to operate the proxy): https://twitter.com/fugueish/status/568258997578371072 Someone will extract the private key in the next few…
Mozilla discussion about what to do with the Superfish cert: Bug 1134506 - Mark "Superfish, Inc." root certificate as untrusted in NSS https://bugzilla.mozilla.org/show_bug.cgi?id=1134506
Re: Lenovo Caught Installing Adware on New Computers
#80Earlier quoted context omitted.
Honestly, I think that's unlikely. This is far too sloppy to have been intentional. There are much better ways to implement a backdoor when you control the OS image. This is just incompetence, plain and simple. Superfish looks like the kind of crapware that pays OEMs to include it in their bundle. Lenovo took the cash and didn't bother to review the code. Superfish, for its part, probably doesn't have the best and br…
Cannot see how this could possibly be true. Having been privy to OS bundling for products, I can assure you there is lengthy contracts, and negotiations, about exactly what is happening. You do no simply walk up to Lenovo and have your "software" installed into the OS without a very detailed contract and pay structure. There also looks to be js injected into pages, which is serving up the ads, and a comment about Len…
If they did know about the problem, they could have fixed it. If the app simply generated a new key as part of first-time use, then it would just be run-of-the-mill crapware rather than a gaping security hole. Even if Lenovo has malicious intent, it would still have been in their best interests to do at least that, yet they didn't. Hence I assume it was incompetence.