Live data from Hacker News

Lenovo Caught Installing Adware on New Computers

thenextweb.com

171–180 of 435 posts

Re: Lenovo Caught Installing Adware on New Computers

#171
post #95

Earlier quoted context omitted.

Is it even possible to buy a Windows laptop right now with only the OS installed? This is exactly why I've been recommending Chromebooks to anyone who asks my advice for about a year now.

All laptops contain something which some people consider bloatware, because it is difficult to draw the line. For instance, is it "only the OS installed" if it includes hardware-specific support for the display adapter, or a fingerprint reader? Anyway, all laptops I have seen include either a generic Windows OS installation disk, or an option to order one for the price of mailing cost. But of course even with these y…

That seems like a pretty easy line to draw. If the software is effectively a device driver - OK; otherwise - no.

Re: Lenovo Caught Installing Adware on New Computers

#172
TheNextWeb does a poor job at reporting technical facts:

"[...] its own self-signed certificate authority which effectively allows the software to snoop on secure connections [...]"

"[...] the certificate allows the software to decrypt secure requests[...]"

As kentonv reported, it's actually the local proxy, installed by the ad(Mal?)ware which is at the center of the MiTM attack. The root, self-signed certificate is installed in order for the attack to be transparent to the victim (i.e. no warning in browser).

Re: Lenovo Caught Installing Adware on New Computers

#175

Earlier quoted context omitted.

Are you sure? Android Chrome proxies all non-HTTPS traffic through a third-party server, by default. So it isn't like the traffic volume is impossible.

Wow, really? I never knew that and some googling didn't find any decent sources. do you have one?

https://developer.chrome.com/multidevice/data-compression

Re: Lenovo Caught Installing Adware on New Computers

#176

Jebus, how far the might IBM laptop line has fallen under the leadership of Lenovo. There was a time when a ThinkPad was arguably the best laptop money could buy. Many companies, including Google, would offer a choice between a ThinkPad or a MacBook, because those were the really reliable choices that were free of shovelware. I even considered buying a Lenovo recently when a pretty nice looking ThinkPad was on sale,…

FWIW, had pretty good experiences with the five Thinkpads, private and company boxes, that I was using at one point or another. There are things that could be (a lot) better - battery life on the W530 and, related to that, the ugly, ginormous brick of a charger that it comes with - but, all things considered, I will remain a Thinkpad customer, since I am not aware of better alternatives. The machines work without fail, and survive incidents like a fall from the overhead luggage compartment on a plane.

Crapware doesn't bother me, since that gets wiped before I start using the box, including the biggest offender of all them crapwares - MS Windows. Unless you're concerned about one of those disk-firmware-rewiring NSA uglies, that's a foolproof solution to the nastyware problem.

Re: Lenovo Caught Installing Adware on New Computers

#177

I'm assuming this only affects you if you're running windows? (Honest question, it's not some firmware based thing from what I've read, but just checking).

Of course... It's just a certificate and proxy that comes by default with the OS as it comes from their factory. You can uninstall the certificate, reinstall Windows, install Linux, etc. and the problem will disappear.

Re: Lenovo Caught Installing Adware on New Computers

#178
post #86

Earlier quoted context omitted.

Microsoft itself has provided Windows installation media for download since Windows 8, including Windows 7 media. All you have to do is read your key off BIOS or the sticker. And of course Windows 10 will be a free download.

Unless things have changed, usually the sticker key is only valid for a certain kind of media. E.g. VLK's only work with VLK images, retail keys only work with retail images...

I usually use a KMS key to install and then use the Windows+Pause dialog to change my product key to the key that is stored in my BIOS.

Re: Lenovo Caught Installing Adware on New Computers

#179
post #51

Earlier quoted context omitted.

I'm curious what legal stance Lenovo customers have here - their secure HTTPS connections are being MITMed intentionally - surely that's hacking, or some national security violation?

"National security" is such a fickle concept. You can bet that if the NSA manages to use this to hoover up some tasty HTTPS, this scandal will be lauded as a big boost to "national security" behind the scenes, and nobody will be punished. For all we know NSA had a hand in engineering this. Of course, if some government data is stolen as a result, then the whole thing will be thrown under the bus and deemed a threat t…

Lenovo is a Chinese company, so it's possible, but you'd think they're more likely to be responsible.

Re: Lenovo Caught Installing Adware on New Computers

#180
Not to minimize Lenovo's guilt for pre-installing adware and not to say MITMing HTTPS fine - it is not! But... I'd rather have a laptop that injects ads in my Google searches than one that sends all my data to some three-letter agency in the US. That being said, we might one day find out that all the Chinese laptops and routers are also sending all the data over to China... That's when the whole story will start being really funny!
Post reply on HN