This is much worse than just installing adware. They install a web proxy which MITMs all web connections, including HTTPS by means of a pre-installed trusted root certificate. The root certificate is the same across all installs, and the private key is present on the machine (necessarily, to operate the proxy): https://twitter.com/fugueish/status/568258997578371072 Someone will extract the private key in the next few…
Lenovo Caught Installing Adware on New Computers
211–220 of 435 posts
Re: Lenovo Caught Installing Adware on New Computers
#212Can someone with one of these laptops connect to https://www.howsmyssl.com/ and post what it says? I'm curious what cipher suites are used from the proxy to the real site.
It says it's "Probably Okay", even when I have Superfish's certificate enabled. (I have the program installed, but the cert sticks around.)
Re: Lenovo Caught Installing Adware on New Computers
#213Earlier quoted context omitted.
The premium isn't as high as you think, particularly if you account for resale value. Didn't Priceonomics do a feature on this?
I'm not sure why anyone buys anything other than a home when accounting for resale value unless they're just trying to pull a pump-and-dump. For laptops, at least, I buy them and use them until they die. I've only owned three laptops in my life.
Re: Lenovo Caught Installing Adware on New Computers
#214Earlier quoted context omitted.
It's not broken, because the Firefox certificate storage isn't empty when you install it. It includes the ones recognized by Mozilla. https://www.mozilla.org/en-US/about/governance/policies/secu...
Sure, but I assume Mozilla doesn't recognize the Lenovo adware, so if all the web traffic is being routed through this proxy, shouldn't firefox have squawked?
Re: Lenovo Caught Installing Adware on New Computers
#215Earlier quoted context omitted.
Is it even possible to buy a Windows laptop right now with only the OS installed? This is exactly why I've been recommending Chromebooks to anyone who asks my advice for about a year now.
With Windows even if you buy the boxed version it still doesn't mean you are free from hardware vendors fuckery. The necessary drivers are quite often bundled with shitware.
(An unnecessary hassle, I agree)
Re: Lenovo Caught Installing Adware on New Computers
#216So basically I have to pay for the hardware and then see annoying ads too?
Re: Lenovo Caught Installing Adware on New Computers
#217Earlier quoted context omitted.
All laptops contain something which some people consider bloatware, because it is difficult to draw the line. For instance, is it "only the OS installed" if it includes hardware-specific support for the display adapter, or a fingerprint reader? Anyway, all laptops I have seen include either a generic Windows OS installation disk, or an option to order one for the price of mailing cost. But of course even with these y…
That seems like a pretty easy line to draw. If the software is effectively a device driver - OK; otherwise - no.
Re: Lenovo Caught Installing Adware on New Computers
#218How do you safely install Mozilla Firefox if you have a broken certificate store?
Re: Lenovo Caught Installing Adware on New Computers
#219Earlier quoted context omitted.
I'm curious what legal stance Lenovo customers have here - their secure HTTPS connections are being MITMed intentionally - surely that's hacking, or some national security violation?
"National security" is such a fickle concept. You can bet that if the NSA manages to use this to hoover up some tasty HTTPS, this scandal will be lauded as a big boost to "national security" behind the scenes, and nobody will be punished. For all we know NSA had a hand in engineering this. Of course, if some government data is stolen as a result, then the whole thing will be thrown under the bus and deemed a threat t…
Re: Lenovo Caught Installing Adware on New Computers
#220Earlier quoted context omitted.
Honestly, I think that's unlikely. This is far too sloppy to have been intentional. There are much better ways to implement a backdoor when you control the OS image. This is just incompetence, plain and simple. Superfish looks like the kind of crapware that pays OEMs to include it in their bundle. Lenovo took the cash and didn't bother to review the code. Superfish, for its part, probably doesn't have the best and br…
How could you add mitm functionality by mistake?
And calling it enhanced is not always an unreasonable interpretation. For instance, take the case of a cheap mobile phone with a very limited bandwidth. You can increase the end user satisfaction considerably if you move some of the functionality to a server layer so that when you browse, the things actually happen somewhere in a cloud and your phone is just displaying the result, without being the actual browser as seen by the site you visit.
Nokia did this with some of the cheaper devices, and I think it was quite OK. It comes down to how much you trust that party, of course, and how critical your communication is.