Live data from Hacker News

Lenovo Caught Installing Adware on New Computers

thenextweb.com

211–220 of 435 posts

Re: Lenovo Caught Installing Adware on New Computers

#211
post #5

This is much worse than just installing adware. They install a web proxy which MITMs all web connections, including HTTPS by means of a pre-installed trusted root certificate. The root certificate is the same across all installs, and the private key is present on the machine (necessarily, to operate the proxy): https://twitter.com/fugueish/status/568258997578371072 Someone will extract the private key in the next few…

[deleted]

Re: Lenovo Caught Installing Adware on New Computers

#212

Can someone with one of these laptops connect to https://www.howsmyssl.com/ and post what it says? I'm curious what cipher suites are used from the proxy to the real site.

It says it's "Probably Okay", even when I have Superfish's certificate enabled. (I have the program installed, but the cert sticks around.)

The site cannot detect that you have an extra root certificate lying around on your computer. If you visit the website without the Superfish program installed, you just evaluate the SSL settings of your browser.

Re: Lenovo Caught Installing Adware on New Computers

#213
post #162
post #140

Earlier quoted context omitted.

The premium isn't as high as you think, particularly if you account for resale value. Didn't Priceonomics do a feature on this?

I'm not sure why anyone buys anything other than a home when accounting for resale value unless they're just trying to pull a pump-and-dump. For laptops, at least, I buy them and use them until they die. I've only owned three laptops in my life.

For a long time a 3-year-old laptop struggled to run the latest eclipse (this may well still be the case). So at that point I'll sell them on to someone with a less intense workload and buy a replacement.

Re: Lenovo Caught Installing Adware on New Computers

#214
post #164

Earlier quoted context omitted.

It's not broken, because the Firefox certificate storage isn't empty when you install it. It includes the ones recognized by Mozilla. https://www.mozilla.org/en-US/about/governance/policies/secu...

Sure, but I assume Mozilla doesn't recognize the Lenovo adware, so if all the web traffic is being routed through this proxy, shouldn't firefox have squawked?

Mozilla has its own proxy settings as well, independent of Windows Control Panel configuration, so a Firefox user appears not to be impacted by the whole thing at all.

Re: Lenovo Caught Installing Adware on New Computers

#215
post #95

Earlier quoted context omitted.

Is it even possible to buy a Windows laptop right now with only the OS installed? This is exactly why I've been recommending Chromebooks to anyone who asks my advice for about a year now.

With Windows even if you buy the boxed version it still doesn't mean you are free from hardware vendors fuckery. The necessary drivers are quite often bundled with shitware.

It's usually possible to unpack the driver installer, find the .INF file, and point Windows at it - this gives you the driver without any of the bloatware.

(An unnecessary hassle, I agree)

Re: Lenovo Caught Installing Adware on New Computers

#217
post #171

Earlier quoted context omitted.

All laptops contain something which some people consider bloatware, because it is difficult to draw the line. For instance, is it "only the OS installed" if it includes hardware-specific support for the display adapter, or a fingerprint reader? Anyway, all laptops I have seen include either a generic Windows OS installation disk, or an option to order one for the price of mailing cost. But of course even with these y…

That seems like a pretty easy line to draw. If the software is effectively a device driver - OK; otherwise - no.

Well, not for me. Like, what about the login management related to fingerprint reader? The reader and device driver are quite useless by themselves if you cannot use them for login. So the laptop vendor obviously bundles the driver and application together. And then you get an app that hooks itself in the place where you normally give your password. And might hook another application which does an alternative login method using the built-in camera (facial recognition).

Re: Lenovo Caught Installing Adware on New Computers

#219
post #51

Earlier quoted context omitted.

I'm curious what legal stance Lenovo customers have here - their secure HTTPS connections are being MITMed intentionally - surely that's hacking, or some national security violation?

"National security" is such a fickle concept. You can bet that if the NSA manages to use this to hoover up some tasty HTTPS, this scandal will be lauded as a big boost to "national security" behind the scenes, and nobody will be punished. For all we know NSA had a hand in engineering this. Of course, if some government data is stolen as a result, then the whole thing will be thrown under the bus and deemed a threat t…

The NSA doesn't need this amateur-hour backdoor. They surely have control of one or more genuine certificate authorities already.

Re: Lenovo Caught Installing Adware on New Computers

#220
post #65

Earlier quoted context omitted.

Honestly, I think that's unlikely. This is far too sloppy to have been intentional. There are much better ways to implement a backdoor when you control the OS image. This is just incompetence, plain and simple. Superfish looks like the kind of crapware that pays OEMs to include it in their bundle. Lenovo took the cash and didn't bother to review the code. Superfish, for its part, probably doesn't have the best and br…

How could you add mitm functionality by mistake?

Because you call it "enhanced functionality featuring cloud services", not a "man in the middle attack".

And calling it enhanced is not always an unreasonable interpretation. For instance, take the case of a cheap mobile phone with a very limited bandwidth. You can increase the end user satisfaction considerably if you move some of the functionality to a server layer so that when you browse, the things actually happen somewhere in a cloud and your phone is just displaying the result, without being the actual browser as seen by the site you visit.

Nokia did this with some of the cheaper devices, and I think it was quite OK. It comes down to how much you trust that party, of course, and how critical your communication is.

Post reply on HN