Live data from Hacker News

Lenovo Caught Installing Adware on New Computers

thenextweb.com

221–230 of 435 posts

Re: Lenovo Caught Installing Adware on New Computers

#221
I'm starting to think we need an equivalent of UL certification or even the old "BABT approved" stickers for consumer protection.

UL provides a bunch of non-obvious to the user but critical for safety rules for mains-connected devices. Likewise users are subject to non-obvious privacy threats from internet-connected devices (leakage of personal information, injected advertising or referral links). These should be at least clearly labelled.

So Android devices would get a "yellow" rating for "transmits personal information securely to Google" and these Lenovo laptops and Samsung TVs would get "red" for "transmits personal information in cleartext".

Re: Lenovo Caught Installing Adware on New Computers

#222
post #64

Earlier quoted context omitted.

Ripped from yesterday's headlines ... ... rewrote the hard-drive firmware of infected computers—a never-before-seen engineering marvel that worked on 12 drive categories from manufacturers including Western Digital, Maxtor, Samsung, IBM, Micron, Toshiba, and Seagate. The malicious firmware created a secret storage vault that survived military-grade disk wiping and reformatting, making sensitive data stolen from victi…

That appears to be the act of a nation-state though. I don't really sweat those, because I'm pretty sure if the NSA really wants in to my machine, I can't stop them.

They don't want in to just your machine though, they want a backdoor in to everyones machine, by default, without cause.

Re: Lenovo Caught Installing Adware on New Computers

#223
post #208

Earlier quoted context omitted.

"Someone will extract the private key in the next few hours, and then HTTPS will be basically completely broken for all Lenovo users -- anyone will be able to spoof any site to them." Do you mean the proxy is remote? That is not the impression I have (otherwise having the private key locally makes no sense). If it's local, then even with the private key extracted, and considering a lot of website force https nowadays…

> we should still have standard crypto between the lenovo computer and the website Standard crypto using that website's certificate. Which could be legit. Or could be an attacker's certificate, signed with this Lenovo root certificate. Some criminals are about to make a lot of money.

Not if the proxy checks the certificate of the site it's connecting to and doesn't trust it's own self-signed cert (there is no point in doing so if it's pure adware). But yeah... I have no idea what it does...

Re: Lenovo Caught Installing Adware on New Computers

#224
post #54

Earlier quoted context omitted.

> with the cheapest drive offered and replacing the drive with an SSD I expect the "cheapest drive" is not an SSD.

hence "replacing the drive with an SSD"

I don't understand the downvotes. The gp probably asked why not just zero-out the bytes. Sure, there's the firmware modification issue. But what I was responding to is why replace. This is the easiest option.

Re: Lenovo Caught Installing Adware on New Computers

#225
post #66
post #8

Earlier quoted context omitted.

Anyway to see if that certificate is on a Lenovo computer? Anyway to remove it? I bought a Lenovo laptop recently, and I was appalled at the amount of crapware that was installed. It's a wonderful laptop at a great price, just too bad about the software.

> It's a wonderful laptop at a great price, just too bad about the software. Lenovo's hardware support for Linux is great so unless there's something keeping you on Windows switching to a good Linux distro usually works fine on these laptops.

Do you trust a hardware vendor that installs MITM stuff on your machine per default to keep the firmware untampered?

There is almost no machine out there running openly auditable code on all components.

Re: Lenovo Caught Installing Adware on New Computers

#226

Jebus, how far the might IBM laptop line has fallen under the leadership of Lenovo. There was a time when a ThinkPad was arguably the best laptop money could buy. Many companies, including Google, would offer a choice between a ThinkPad or a MacBook, because those were the really reliable choices that were free of shovelware. I even considered buying a Lenovo recently when a pretty nice looking ThinkPad was on sale,…

I have a X230 and I'm super happy with it. The quality is beyond everything I have experienced with laptops. I have a newer Dell E-series at work now and it's ok, but lack the same quality feel imo.

I suspect the cheaper Lenovo laptops are shitty though.

Re: Lenovo Caught Installing Adware on New Computers

#227
Some more URLs...

https://www.superfish.com/ws/sf_code.jsp

https://www.superfish.com/ws/sf_conduit.jsp

https://www.superfish.com/ws/sf_conduit_mam.jsp

https://www.superfish.com/ws/sfw.jsp

https://www.superfish.com/ws/sf_main.jsp

https://www.superfish.com/ws/getCouponsSupportedSites.action

https://www.superfish.com/ws/getSupportedSitesJSON.action

Re: Lenovo Caught Installing Adware on New Computers

#228

Earlier quoted context omitted.

"National security" is such a fickle concept. You can bet that if the NSA manages to use this to hoover up some tasty HTTPS, this scandal will be lauded as a big boost to "national security" behind the scenes, and nobody will be punished. For all we know NSA had a hand in engineering this. Of course, if some government data is stolen as a result, then the whole thing will be thrown under the bus and deemed a threat t…

The NSA doesn't need this amateur-hour backdoor. They surely have control of one or more genuine certificate authorities already.

Impersonating a CA is not transparent and risks losing that CA if anyone finds out it's forging certs. They probably can do that, but it's a risky nuclear option.

This is a transparent dragnet that can easily be blamed away, which has been shown to be much more preferable in the NSA's M.O.

Re: Lenovo Caught Installing Adware on New Computers

#229
post #129

I don't see myself ever bothering to keep the default windows install on a thinkpad but this really hurts my impression of the company regardless. I've had my eye on the new X1s and had planned to upgrade my X201 this year but now I'm having second thoughts. Who if anyone has taken over the place of great laptop for linux / development?

The new Dell XPS 13 looks like a very nice laptop. I have the previous version and it works very well with Linux.

I used the XPS 13 as my main machine from 2013 to late 2014 (when I switched to a MBPr). It was a nice machine initially but I found that it ended up looking pretty tattered (particularly the plastic edge, which looks and feels cheap and a bit fragile in the long run). Most annoyingly, it had a tendency to overheat, particularly when dual booting into Ubuntu. After about 20 minutes, I couldn't leave the thing on my knees - had to find a table. Both the "tablet/screen" and the base were affected.

It was portable and powerful enough, but the MBPr gives me a much better overall experience. At half, perhaps 2/3 of the price of the 13" MBPr, it might still be worth it.

Re: Lenovo Caught Installing Adware on New Computers

#230
post #133

Earlier quoted context omitted.

You can buy "Microsoft Signature" machines from the MS stores and online. Hopefully the words will spread.

Wow haven't heard of those before, actually kind of like the idea of buying a PC and knowing there is an untouched version of Windows on it (unless you consider IE malware) :)

I bought my last laptop this way, and it's been very satisfying to own. There was no funny business, it's just straight-up Windows. It didn't even have any stickers on it except for a tiny Intel sticker.
Post reply on HN