Live data from Hacker News

Lenovo Caught Installing Adware on New Computers

thenextweb.com

151–160 of 435 posts

Re: Lenovo Caught Installing Adware on New Computers

#151
post #51
post #5

This is much worse than just installing adware. They install a web proxy which MITMs all web connections, including HTTPS by means of a pre-installed trusted root certificate. The root certificate is the same across all installs, and the private key is present on the machine (necessarily, to operate the proxy): https://twitter.com/fugueish/status/568258997578371072 Someone will extract the private key in the next few…

I'm curious what legal stance Lenovo customers have here - their secure HTTPS connections are being MITMed intentionally - surely that's hacking, or some national security violation?

"National security" is such a fickle concept.

You can bet that if the NSA manages to use this to hoover up some tasty HTTPS, this scandal will be lauded as a big boost to "national security" behind the scenes, and nobody will be punished. For all we know NSA had a hand in engineering this.

Of course, if some government data is stolen as a result, then the whole thing will be thrown under the bus and deemed a threat to "national security".

I hope anyone who uses terms like "national security" does it in full awareness of what Orwell meant by newspeak and doublethink.

Re: Lenovo Caught Installing Adware on New Computers

#152
post #112
post #5

This is much worse than just installing adware. They install a web proxy which MITMs all web connections, including HTTPS by means of a pre-installed trusted root certificate. The root certificate is the same across all installs, and the private key is present on the machine (necessarily, to operate the proxy): https://twitter.com/fugueish/status/568258997578371072 Someone will extract the private key in the next few…

I'm confused; if Firefox doesn't use the system certificates, shouldn't Firefox users have been seeing visibly broken HTTPS from day one?

[deleted]

Re: Lenovo Caught Installing Adware on New Computers

#153
post #129

I don't see myself ever bothering to keep the default windows install on a thinkpad but this really hurts my impression of the company regardless. I've had my eye on the new X1s and had planned to upgrade my X201 this year but now I'm having second thoughts. Who if anyone has taken over the place of great laptop for linux / development?

The new Dell XPS 13 looks like a very nice laptop. I have the previous version and it works very well with Linux.

The new one has hardware issues that are still being worked out. Follow @majorhayden on twitter for more.

Re: Lenovo Caught Installing Adware on New Computers

#154

I don't see myself ever bothering to keep the default windows install on a thinkpad but this really hurts my impression of the company regardless. I've had my eye on the new X1s and had planned to upgrade my X201 this year but now I'm having second thoughts. Who if anyone has taken over the place of great laptop for linux / development?

The Novena laptop was created specifically because you can't trust any of the big manufacturers not to do this at a deeper level. (Detecting this kind of attack in software is way easier than finding something deeper.)

https://www.crowdsupply.com/kosagi/novena-open-laptop

Re: Lenovo Caught Installing Adware on New Computers

#155

Was just about to purchase a lenovo... although I would have wiped it and installed linux immediately this has caused me to look elsewhere. when will companies learn this kind of behavior is toxic to their business?

Unfortunately a very small proportion of potential customers are going to hear or care about this... it's about as toxic to their business as stepping in some stinging nettles is toxic to me.

I don't know; if this gets into the news cycle (which it should), I think it will be a huge problem for lenovo. The people buying one of these to run Linux likely already understand the implications and are reading about it now. The rest of the consumer base need only hear "someone can intercept your banking password" and they will take notice.

There has been an uptick in computer security related news stories lately. I think the tide may be changing, albeit slowly.

Re: Lenovo Caught Installing Adware on New Computers

#156
post #126

Ugh. So for "developer-tier" laptops, i.e. not a netbook, does that pretty much leave Apple as the sole non-shit laptop maker? Is there a chromebook out there that runs linux pretty well if you pull chromeOS off? You pay a hefty premium for that backlit Apple logo on the lid, and I'd prefer to get something a little more down-to-earth.

A colleague uses the Dell XPS 13 and it's pretty good; I'm eyeing that for my next machine.

Re: Lenovo Caught Installing Adware on New Computers

#159
post #94
post #80

Earlier quoted context omitted.

Oh I'm sure they had lots of meetings about the contracts and pay structure, and they may have done testing to make sure it didn't break things, but apparently no one did a security review. Sadly, this doesn't surprise me that much. If they did know about the problem, they could have fixed it. If the app simply generated a new key as part of first-time use, then it would just be run-of-the-mill crapware rather than a…

but apparently no one did a security review It doesn't take a "security review" to spot a gaping security and privacy violation like this. Any engineer with even the slightest clue of how a browser and "the internet" works would have called this out during the first "How does this product work?"-presentation. Let's not pretend Lenovo is staffed with monkeys.

How many engineers do you think were in the "how it works" meeting?

Re: Lenovo Caught Installing Adware on New Computers

#160

Can someone with one of these laptops connect to https://www.howsmyssl.com/ and post what it says? I'm curious what cipher suites are used from the proxy to the real site.

It says it's "Probably Okay", even when I have Superfish's certificate enabled. (I have the program installed, but the cert sticks around.)
Post reply on HN