Lenovo Caught Installing Adware on New Computers
111–120 of 435 posts
Re: Lenovo Caught Installing Adware on New Computers
#112This is much worse than just installing adware. They install a web proxy which MITMs all web connections, including HTTPS by means of a pre-installed trusted root certificate. The root certificate is the same across all installs, and the private key is present on the machine (necessarily, to operate the proxy): https://twitter.com/fugueish/status/568258997578371072 Someone will extract the private key in the next few…
Re: Lenovo Caught Installing Adware on New Computers
#113Re: Lenovo Caught Installing Adware on New Computers
#114Re: Lenovo Caught Installing Adware on New Computers
#115Earlier quoted context omitted.
Oh I'm sure they had lots of meetings about the contracts and pay structure, and they may have done testing to make sure it didn't break things, but apparently no one did a security review. Sadly, this doesn't surprise me that much. If they did know about the problem, they could have fixed it. If the app simply generated a new key as part of first-time use, then it would just be run-of-the-mill crapware rather than a…
but apparently no one did a security review It doesn't take a "security review" to spot a gaping security and privacy violation like this. Any engineer with even the slightest clue of how a browser and "the internet" works would have called this out during the first "How does this product work?"-presentation. Let's not pretend Lenovo is staffed with monkeys.
Remember stuff like this:
http://www.cryptofails.com/post/70059600123/saltstack-rsa-e-...
(Which, possibly unfairly, is one reason I'm leaning more towards ansible than saltstack to this day -- I mean, if stuff like that got through... what else, in more complex areas of the system?)
Re: Lenovo Caught Installing Adware on New Computers
#116Earlier quoted context omitted.
Oh I'm sure they had lots of meetings about the contracts and pay structure, and they may have done testing to make sure it didn't break things, but apparently no one did a security review. Sadly, this doesn't surprise me that much. If they did know about the problem, they could have fixed it. If the app simply generated a new key as part of first-time use, then it would just be run-of-the-mill crapware rather than a…
but apparently no one did a security review It doesn't take a "security review" to spot a gaping security and privacy violation like this. Any engineer with even the slightest clue of how a browser and "the internet" works would have called this out during the first "How does this product work?"-presentation. Let's not pretend Lenovo is staffed with monkeys.
"Any engineer" means something in HN, but we're not talking about "people who read HN" levels of engineer here, don't be mistaken.
Some people that have had no or limited experience with software are assigned to software projects, and that's the issue with companies like Lenovo.
Re: Lenovo Caught Installing Adware on New Computers
#117Was just about to purchase a lenovo... although I would have wiped it and installed linux immediately this has caused me to look elsewhere. when will companies learn this kind of behavior is toxic to their business?
Unfortunately a very small proportion of potential customers are going to hear or care about this... it's about as toxic to their business as stepping in some stinging nettles is toxic to me.
Re: Lenovo Caught Installing Adware on New Computers
#118Earlier quoted context omitted.
Asus is about it.
I thought so too, but my recent experience with a Zenbook has changed my view. WiFi drivers were so bad it took half a year after my purchase before the connection became stable (not dropping every 15 minutes requiring a reboot). Touchpad drivers were also a mess with awful kinetic scrolling. And just couple of weeks ago it stopped booting Windows altogehter (something related to ACPI I guess, Linux works if I don't…
The WiFi drivers are made by Intel, but yes, they were terrible (blue screen). I had to downgrade back to the drivers that came with Windows for while but the latest versions seem to be fine. I'm using some stock touchpad drivers that don't seem to have any kinetic scrolling.
But I'm the person who brought this to the attention of Hacker News: https://news.ycombinator.com/item?id=8546702
Basically after installing just about everything the laptop comes with, it seems to be running great. :)
Re: Lenovo Caught Installing Adware on New Computers
#119This is much worse than just installing adware. They install a web proxy which MITMs all web connections, including HTTPS by means of a pre-installed trusted root certificate. The root certificate is the same across all installs, and the private key is present on the machine (necessarily, to operate the proxy): https://twitter.com/fugueish/status/568258997578371072 Someone will extract the private key in the next few…
I'm curious what legal stance Lenovo customers have here - their secure HTTPS connections are being MITMed intentionally - surely that's hacking, or some national security violation?
of course they are - Lenovo customers have signed the agreement that this is ok when they started the machine the first time
Re: Lenovo Caught Installing Adware on New Computers
#120Lenovo going down the drain. All they had to do was continue the Thinkpad legacy left by IBM. It's honestly breathtaking how badly they've fucked up. After the touch-based function keys, ruining the trackpoint buttons and now this. It's unbelievable.