Live data from Hacker News

Lenovo Caught Installing Adware on New Computers

thenextweb.com

141–150 of 435 posts

Re: Lenovo Caught Installing Adware on New Computers

#141
post #112
post #5

This is much worse than just installing adware. They install a web proxy which MITMs all web connections, including HTTPS by means of a pre-installed trusted root certificate. The root certificate is the same across all installs, and the private key is present on the machine (necessarily, to operate the proxy): https://twitter.com/fugueish/status/568258997578371072 Someone will extract the private key in the next few…

I'm confused; if Firefox doesn't use the system certificates, shouldn't Firefox users have been seeing visibly broken HTTPS from day one?

It's not broken, because the Firefox certificate storage isn't empty when you install it. It includes the ones recognized by Mozilla.

https://www.mozilla.org/en-US/about/governance/policies/secu...

Re: Lenovo Caught Installing Adware on New Computers

#142
post #94

Earlier quoted context omitted.

but apparently no one did a security review It doesn't take a "security review" to spot a gaping security and privacy violation like this. Any engineer with even the slightest clue of how a browser and "the internet" works would have called this out during the first "How does this product work?"-presentation. Let's not pretend Lenovo is staffed with monkeys.

You're so optimistic it hurts "Any engineer" means something in HN, but we're not talking about "people who read HN" levels of engineer here, don't be mistaken. Some people that have had no or limited experience with software are assigned to software projects, and that's the issue with companies like Lenovo.

Operations the size of Lenovo have a fairly intense vetting process before a product goes to market.

I find it very hard to believe that no red flags were raised by any of the engineers, managers and especially lawyers who must have screened this "feature" for problems.

It seems more plausible that the problem was known from the beginning (it is by design after all) and Lenovo decided to risk it.

Re: Lenovo Caught Installing Adware on New Computers

#143
post #95

Jebus, how far the might IBM laptop line has fallen under the leadership of Lenovo. There was a time when a ThinkPad was arguably the best laptop money could buy. Many companies, including Google, would offer a choice between a ThinkPad or a MacBook, because those were the really reliable choices that were free of shovelware. I even considered buying a Lenovo recently when a pretty nice looking ThinkPad was on sale,…

Is it even possible to buy a Windows laptop right now with only the OS installed? This is exactly why I've been recommending Chromebooks to anyone who asks my advice for about a year now.

All laptops contain something which some people consider bloatware, because it is difficult to draw the line.

For instance, is it "only the OS installed" if it includes hardware-specific support for the display adapter, or a fingerprint reader?

Anyway, all laptops I have seen include either a generic Windows OS installation disk, or an option to order one for the price of mailing cost. But of course even with these you might have something included which you do not consider "only the OS".

Re: Lenovo Caught Installing Adware on New Computers

#145
post #65
post #55

Earlier quoted context omitted.

naturally oblivious to the security implications Rest assured Lenovo was perfectly aware of the security and privacy implications of this feature from the beginning. They merely try to sound oblivious because their laywers hope that will soften the legal and media repercussions.

Honestly, I think that's unlikely. This is far too sloppy to have been intentional. There are much better ways to implement a backdoor when you control the OS image. This is just incompetence, plain and simple. Superfish looks like the kind of crapware that pays OEMs to include it in their bundle. Lenovo took the cash and didn't bother to review the code. Superfish, for its part, probably doesn't have the best and br…

They probably tasked a junior programmer with working around SSL

I don't think I've seen a junior anything who was informed and insightful enough to write a network proxy, including SSL support, and the necessary certificate work.

Re: Lenovo Caught Installing Adware on New Computers

#147
post #133
post #95

Earlier quoted context omitted.

Is it even possible to buy a Windows laptop right now with only the OS installed? This is exactly why I've been recommending Chromebooks to anyone who asks my advice for about a year now.

You can buy "Microsoft Signature" machines from the MS stores and online. Hopefully the words will spread.

MSFT should really be pushing these more, seems like a great opportunity

Re: Lenovo Caught Installing Adware on New Computers

#148
post #86

Earlier quoted context omitted.

Microsoft itself has provided Windows installation media for download since Windows 8, including Windows 7 media. All you have to do is read your key off BIOS or the sticker. And of course Windows 10 will be a free download.

Unless things have changed, usually the sticker key is only valid for a certain kind of media. E.g. VLK's only work with VLK images, retail keys only work with retail images...

Just recently installed Windows 7 Pro on a HP ProBook thing:

- looked up the Windows and Office license keys of the existing installation, using an utility

- download Windows 7 disk image from Microsoft and burn on a DVD

- take out the old disk with recovery partitions and installation with crappy bloatware

- put in a new SSD disk, boot DVD to install OS and install Office

- download and install HP specific drivers for peripherals (display adapter, fingerprint reader, wlan/3g, whatever)

- enjoy a relatively bloat-free Windows experience with improved battery life

Re: Lenovo Caught Installing Adware on New Computers

#149
post #102

Jebus, how far the might IBM laptop line has fallen under the leadership of Lenovo. There was a time when a ThinkPad was arguably the best laptop money could buy. Many companies, including Google, would offer a choice between a ThinkPad or a MacBook, because those were the really reliable choices that were free of shovelware. I even considered buying a Lenovo recently when a pretty nice looking ThinkPad was on sale,…

I've had great experiences with the ThinkPad T420, but after this news I'll likely never be buying a Lenovo product again. A damn shame.

I'm tempted to believe that's the last great Thinkpad. Until this morning I was being tempted by the new X1 Carbon, even with its non-traditional keyboard. Not so much now.

Re: Lenovo Caught Installing Adware on New Computers

#150

I'm surprised that this is just now news. I received complaints from people participating in our beta trial ( http://sketchtogether.com ) from as early as October 22nd, 2014 that our website was broken, and it was because of Superfish being installed on their lenovo laptops. When they uninstalled Superfish, our webpage started working again. Superfish injected a line of code that referenced "sf_main.jsp" from a remot…

For reference, it's safe to assume that code is under copyright, but don't take it down: this is almost classic fair use.
Post reply on HN