Earlier quoted context omitted.
I thought that Chrome checks and reports that google.com certificate is a google issued certificate. How did this mitm attack not pop up massive warnings in chrome?
Chrome ignores Trusted Root Certificates when checking certificate pinning.
Lenovo Caught Installing Adware on New Computers
241–250 of 435 posts
Re: Lenovo Caught Installing Adware on New Computers
#242Jebus, how far the might IBM laptop line has fallen under the leadership of Lenovo. There was a time when a ThinkPad was arguably the best laptop money could buy. Many companies, including Google, would offer a choice between a ThinkPad or a MacBook, because those were the really reliable choices that were free of shovelware. I even considered buying a Lenovo recently when a pretty nice looking ThinkPad was on sale,…
Is it even possible to buy a Windows laptop right now with only the OS installed? This is exactly why I've been recommending Chromebooks to anyone who asks my advice for about a year now.
Re: Lenovo Caught Installing Adware on New Computers
#243Earlier quoted context omitted.
I thought that had to do with the fact that they're a chinese owned company and if say the CIA makes a large order (or any order really) the chinese government might step in and force malware to be installed.
I can't see why it would matter, since literally every laptop is made in China already. Plus the vast majority of computer components.
As opposed to Lenovo agreeing to implement a backdoor? I'm not sure either.
Re: Lenovo Caught Installing Adware on New Computers
#244I have had first hand recent experience with this. I bought a new Lenovo laptop at the start of the month. When I put a new webpage online using my webhost's cPanel to edit the raw HTML everything seemed fine, until a friend asked about a 'best-deals' script running on the page. The Malware / Adware was intercepting & inserting a script not only into pages I was viewing but also pages I was putting online. Very, very…
They would have to have some sort of software that is able to detect that you are connecting to cpanel and then act on your behalf. That is significantly more involved and more malicious than "just" intercepting html in flight and injecting adds.
Re: Lenovo Caught Installing Adware on New Computers
#245Earlier quoted context omitted.
Here's Lenovo trying to justify the presence of this software, naturally oblivious to the security implications: https://forums.lenovo.com/t5/Lenovo-P-Y-and-Z-series/Lenovo-...
naturally oblivious to the security implications Rest assured Lenovo was perfectly aware of the security and privacy implications of this feature from the beginning. They merely try to sound oblivious because their laywers hope that will soften the legal and media repercussions.
I honestly don't know why Lenovo (and others) still make these third party deals. Just ship the machine with a blank OS, or install a vetted selection of open-source software (7zip, VLC, LibreOffice if they want). Just don't install crapware for the mediocre kickback it generates!
Re: Lenovo Caught Installing Adware on New Computers
#246I don't see myself ever bothering to keep the default windows install on a thinkpad but this really hurts my impression of the company regardless. I've had my eye on the new X1s and had planned to upgrade my X201 this year but now I'm having second thoughts. Who if anyone has taken over the place of great laptop for linux / development?
The new Dell XPS 13 looks like a very nice laptop. I have the previous version and it works very well with Linux.
Re: Lenovo Caught Installing Adware on New Computers
#247Ugh. So for "developer-tier" laptops, i.e. not a netbook, does that pretty much leave Apple as the sole non-shit laptop maker? Is there a chromebook out there that runs linux pretty well if you pull chromeOS off? You pay a hefty premium for that backlit Apple logo on the lid, and I'd prefer to get something a little more down-to-earth.
A colleague uses the Dell XPS 13 and it's pretty good; I'm eyeing that for my next machine.
Re: Lenovo Caught Installing Adware on New Computers
#248Earlier quoted context omitted.
Sure, but I assume Mozilla doesn't recognize the Lenovo adware, so if all the web traffic is being routed through this proxy, shouldn't firefox have squawked?
Mozilla has its own proxy settings as well, independent of Windows Control Panel configuration, so a Firefox user appears not to be impacted by the whole thing at all.
https://bugzilla.mozilla.org/show_bug.cgi?id=1134506
Down around 0200 PST 2015-02-19
EDIT: credit
[1] cpeterso https://news.ycombinator.com/item?id=9072642
Re: Lenovo Caught Installing Adware on New Computers
#249Jebus, how far the might IBM laptop line has fallen under the leadership of Lenovo. There was a time when a ThinkPad was arguably the best laptop money could buy. Many companies, including Google, would offer a choice between a ThinkPad or a MacBook, because those were the really reliable choices that were free of shovelware. I even considered buying a Lenovo recently when a pretty nice looking ThinkPad was on sale,…
Hardware is good, in case of trouble on-site warranty works well (once you've learned your way through the ibm website). Be informed about what you buy, skip the comically broken models (see adaptive keyboard) use common sense and your thinkpad will be good. Nothing out of the usual when buying tech stuff.
Though in a not so distant future if lenovo declines continue, it may be wise to stay away from their brand altogether.
[1]: http://arstechnica.com/staff/2014/01/stop-trying-to-innovate...
Re: Lenovo Caught Installing Adware on New Computers
#250I have had first hand recent experience with this. I bought a new Lenovo laptop at the start of the month. When I put a new webpage online using my webhost's cPanel to edit the raw HTML everything seemed fine, until a friend asked about a 'best-deals' script running on the page. The Malware / Adware was intercepting & inserting a script not only into pages I was viewing but also pages I was putting online. Very, very…
I don't believe that. They would have to have some sort of software that is able to detect that you are connecting to cpanel and then act on your behalf. That is significantly more involved and more malicious than "just" intercepting html in flight and injecting adds.
Either way, this was a downloaded HTML file which was then copied into cPanel. I never viewed or edited the file between its download from JSbin & pasting into cPanel.
The Malware was affecting files & not just pages viewed in browser. Nasty stuff.