Live data from Hacker News

Lenovo Caught Installing Adware on New Computers

thenextweb.com

241–250 of 435 posts

Re: Lenovo Caught Installing Adware on New Computers

#241
post #189
post #170

Earlier quoted context omitted.

I thought that Chrome checks and reports that google.com certificate is a google issued certificate. How did this mitm attack not pop up massive warnings in chrome?

Chrome ignores Trusted Root Certificates when checking certificate pinning.

But doesn't that defeat the purpose? If a trusted Chinese certificate authority issues some certificate on google.com for China to perform MITM attack, and Chrome ignores anything signed by a valid root certificate, it will never report this attack. I thought the point of certificate pinning is precisely that only a single authority can sign a certificate for a website.

Re: Lenovo Caught Installing Adware on New Computers

#242
post #95

Jebus, how far the might IBM laptop line has fallen under the leadership of Lenovo. There was a time when a ThinkPad was arguably the best laptop money could buy. Many companies, including Google, would offer a choice between a ThinkPad or a MacBook, because those were the really reliable choices that were free of shovelware. I even considered buying a Lenovo recently when a pretty nice looking ThinkPad was on sale,…

Is it even possible to buy a Windows laptop right now with only the OS installed? This is exactly why I've been recommending Chromebooks to anyone who asks my advice for about a year now.

The alternative to this is buying an OEM copy of your Windows OS, and hoping the driver situation works out.

Re: Lenovo Caught Installing Adware on New Computers

#243
post #193
post #99

Earlier quoted context omitted.

I thought that had to do with the fact that they're a chinese owned company and if say the CIA makes a large order (or any order really) the chinese government might step in and force malware to be installed.

I can't see why it would matter, since literally every laptop is made in China already. Plus the vast majority of computer components.

Maybe it's too much of a risk if exposed for the manufacturing industry had they added a backdoor to a foreign customer's component without their knowledge?

As opposed to Lenovo agreeing to implement a backdoor? I'm not sure either.

Re: Lenovo Caught Installing Adware on New Computers

#244

I have had first hand recent experience with this. I bought a new Lenovo laptop at the start of the month. When I put a new webpage online using my webhost's cPanel to edit the raw HTML everything seemed fine, until a friend asked about a 'best-deals' script running on the page. The Malware / Adware was intercepting & inserting a script not only into pages I was viewing but also pages I was putting online. Very, very…

I don't believe that.

They would have to have some sort of software that is able to detect that you are connecting to cpanel and then act on your behalf. That is significantly more involved and more malicious than "just" intercepting html in flight and injecting adds.

Re: Lenovo Caught Installing Adware on New Computers

#245
post #55
post #12

Earlier quoted context omitted.

Here's Lenovo trying to justify the presence of this software, naturally oblivious to the security implications: https://forums.lenovo.com/t5/Lenovo-P-Y-and-Z-series/Lenovo-...

naturally oblivious to the security implications Rest assured Lenovo was perfectly aware of the security and privacy implications of this feature from the beginning. They merely try to sound oblivious because their laywers hope that will soften the legal and media repercussions.

No, this is an example of the Lenovo sales / marketing people making distribution deals with dodgy third-party companies. The people who design the machines don't make the decision to ship MITM proxies on them.

I honestly don't know why Lenovo (and others) still make these third party deals. Just ship the machine with a blank OS, or install a vetted selection of open-source software (7zip, VLC, LibreOffice if they want). Just don't install crapware for the mediocre kickback it generates!

Re: Lenovo Caught Installing Adware on New Computers

#246
post #129

I don't see myself ever bothering to keep the default windows install on a thinkpad but this really hurts my impression of the company regardless. I've had my eye on the new X1s and had planned to upgrade my X201 this year but now I'm having second thoughts. Who if anyone has taken over the place of great laptop for linux / development?

The new Dell XPS 13 looks like a very nice laptop. I have the previous version and it works very well with Linux.

I have one of the Ubuntu XPS 13s. It is a nice machine but battery is woeful after < 2 years of use.

Re: Lenovo Caught Installing Adware on New Computers

#247
post #126

Ugh. So for "developer-tier" laptops, i.e. not a netbook, does that pretty much leave Apple as the sole non-shit laptop maker? Is there a chromebook out there that runs linux pretty well if you pull chromeOS off? You pay a hefty premium for that backlit Apple logo on the lid, and I'd prefer to get something a little more down-to-earth.

A colleague uses the Dell XPS 13 and it's pretty good; I'm eyeing that for my next machine.

Watch out, batter life is pretty crap! (About 2 hrs on my < 2yr old one)

Re: Lenovo Caught Installing Adware on New Computers

#248
post #164

Earlier quoted context omitted.

Sure, but I assume Mozilla doesn't recognize the Lenovo adware, so if all the web traffic is being routed through this proxy, shouldn't firefox have squawked?

Mozilla has its own proxy settings as well, independent of Windows Control Panel configuration, so a Firefox user appears not to be impacted by the whole thing at all.

It's not clear to me. Just a few minutes ago (and after your post) this appeared on mozilla discussion forum given by [1] above (will come back to credit this- didn't copy and don't remember (and can't see!)).

https://bugzilla.mozilla.org/show_bug.cgi?id=1134506

Down around 0200 PST 2015-02-19

EDIT: credit

[1] cpeterso https://news.ycombinator.com/item?id=9072642

Re: Lenovo Caught Installing Adware on New Computers

#249

Jebus, how far the might IBM laptop line has fallen under the leadership of Lenovo. There was a time when a ThinkPad was arguably the best laptop money could buy. Many companies, including Google, would offer a choice between a ThinkPad or a MacBook, because those were the really reliable choices that were free of shovelware. I even considered buying a Lenovo recently when a pretty nice looking ThinkPad was on sale,…

I can attest that thinkpad quality is on the decline, linux support too (not mentioning the stupidity of experimenting with new ways of doing keyboards[1]) but it's not that bad yet.

Hardware is good, in case of trouble on-site warranty works well (once you've learned your way through the ibm website). Be informed about what you buy, skip the comically broken models (see adaptive keyboard) use common sense and your thinkpad will be good. Nothing out of the usual when buying tech stuff.

Though in a not so distant future if lenovo declines continue, it may be wise to stay away from their brand altogether.

[1]: http://arstechnica.com/staff/2014/01/stop-trying-to-innovate...

Re: Lenovo Caught Installing Adware on New Computers

#250
post #244

I have had first hand recent experience with this. I bought a new Lenovo laptop at the start of the month. When I put a new webpage online using my webhost's cPanel to edit the raw HTML everything seemed fine, until a friend asked about a 'best-deals' script running on the page. The Malware / Adware was intercepting & inserting a script not only into pages I was viewing but also pages I was putting online. Very, very…

I don't believe that. They would have to have some sort of software that is able to detect that you are connecting to cpanel and then act on your behalf. That is significantly more involved and more malicious than "just" intercepting html in flight and injecting adds.

If it wasn't intercepted from the cPanel then it may have been intercepted from the HTML file download from JSbin (which I copied into cPanel).

Either way, this was a downloaded HTML file which was then copied into cPanel. I never viewed or edited the file between its download from JSbin & pasting into cPanel.

The Malware was affecting files & not just pages viewed in browser. Nasty stuff.

Post reply on HN