Live data from Hacker News

Lenovo Caught Installing Adware on New Computers

thenextweb.com

261–270 of 435 posts

Re: Lenovo Caught Installing Adware on New Computers

#262

I have had first hand recent experience with this. I bought a new Lenovo laptop at the start of the month. When I put a new webpage online using my webhost's cPanel to edit the raw HTML everything seemed fine, until a friend asked about a 'best-deals' script running on the page. The Malware / Adware was intercepting & inserting a script not only into pages I was viewing but also pages I was putting online. Very, very…

WHAT THE ACTUAL FUCK. Never buying Lenovo again.

You can just get precise Windows version that was installed and format all the drives (including recovery) and then do clean install.

Result: no bloat and no malware

Re: Lenovo Caught Installing Adware on New Computers

#263

I'm surprised that this is just now news. I received complaints from people participating in our beta trial ( http://sketchtogether.com ) from as early as October 22nd, 2014 that our website was broken, and it was because of Superfish being installed on their lenovo laptops. When they uninstalled Superfish, our webpage started working again. Superfish injected a line of code that referenced "sf_main.jsp" from a remot…

Interestingly it is disabled for Google services (making the article's image irrelevant :). If this regex matches, `nofish` is set true, which disables superfish: /^https?:\/\/(www|play)\.google\.(?!com\/analytics\/)/i Also, if you add a tag, it gets disabled as well. Possibly some agreement with Google, like the ones they tend to make with ad-blockers? ( http://www.theverge.com/2015/2/2/7963577/google-ads-get-thro..…

That doesn't disable the part of Superfish that MITMs SSL connnections to sites - in fact, it obviously can't because that check can't even run until they've MITMed the connection and injected the code that includes those checks.

Re: Lenovo Caught Installing Adware on New Computers

#264
post #229
post #129

Earlier quoted context omitted.

The new Dell XPS 13 looks like a very nice laptop. I have the previous version and it works very well with Linux.

I used the XPS 13 as my main machine from 2013 to late 2014 (when I switched to a MBPr). It was a nice machine initially but I found that it ended up looking pretty tattered (particularly the plastic edge, which looks and feels cheap and a bit fragile in the long run). Most annoyingly, it had a tendency to overheat, particularly when dual booting into Ubuntu. After about 20 minutes, I couldn't leave the thing on my k…

> (particularly the plastic edge, which looks and feels cheap and a bit fragile in the long run)

I wish more computers were built out of whatever my EEE PC 701 was. It was matte and almost indestructible.

Re: Lenovo Caught Installing Adware on New Computers

#265
post #95

Jebus, how far the might IBM laptop line has fallen under the leadership of Lenovo. There was a time when a ThinkPad was arguably the best laptop money could buy. Many companies, including Google, would offer a choice between a ThinkPad or a MacBook, because those were the really reliable choices that were free of shovelware. I even considered buying a Lenovo recently when a pretty nice looking ThinkPad was on sale,…

Is it even possible to buy a Windows laptop right now with only the OS installed? This is exactly why I've been recommending Chromebooks to anyone who asks my advice for about a year now.

Microsoft Surface is straight from MS - no bloat/malware. However I wouldn't buy it now since v4 is soon to come.

Re: Lenovo Caught Installing Adware on New Computers

#266
post #66

Earlier quoted context omitted.

> It's a wonderful laptop at a great price, just too bad about the software. Lenovo's hardware support for Linux is great so unless there's something keeping you on Windows switching to a good Linux distro usually works fine on these laptops.

Do you trust a hardware vendor that installs MITM stuff on your machine per default to keep the firmware untampered? There is almost no machine out there running openly auditable code on all components.

So what? At least with the software part you remove a large portion of the risks. It's better to go half way than doing nothing about it, and hardware tampering for a company could be more risky since they would have to do mass recall if discovered.

Re: Lenovo Caught Installing Adware on New Computers

#267
post #208

Earlier quoted context omitted.

> we should still have standard crypto between the lenovo computer and the website Standard crypto using that website's certificate. Which could be legit. Or could be an attacker's certificate, signed with this Lenovo root certificate. Some criminals are about to make a lot of money.

Not if the proxy checks the certificate of the site it's connecting to and doesn't trust it's own self-signed cert (there is no point in doing so if it's pure adware). But yeah... I have no idea what it does...

I honestly doubt that someone who was clueless and lazy enough to use the same self-signed certificate on all machines would put in the extra effort not to trust that certificate. Besides, the certificate is left behind after the software's uninstalled and no longer proxying connections.

Re: Lenovo Caught Installing Adware on New Computers

#268
post #240

I used a ThinkPad 700 in 1992 and have bought ThinkPads ever since. Lenovo keep trying to ruin them while ignoring customers telling them to stop. A ThinkPad 1. Is robust 2. Is reliable 3. Is black 4. Has only useful software pre-installed, from the manufacturer (e.g. the Lenovo thing which updates drivers) 5. Has a TrackPoint 6. Has a consistent keyboard layout 7. Has hardware buttons ('mouse', function keys, etc.)…

Agreed. Somebody really needs to start making Thinkpads again. Lenovo ain't it. All they've done is manage to kill the brand.

Re: Lenovo Caught Installing Adware on New Computers

#269

Can someone with one of these laptops connect to https://www.howsmyssl.com/ and post what it says? I'm curious what cipher suites are used from the proxy to the real site.

First thing I did when I saw that URL was to run it through Qualys' SSL Labs test. Multiple issues, no forward secrecy, weak ciphers, grade set to 'C'. Oh, the irony.

https://www.ssllabs.com/ssltest/analyze.html?d=howsmyssl.com

Re: Lenovo Caught Installing Adware on New Computers

#270
Superfish really creeped me out last November when I got a new Lenovo laptop. I first noticed it when using Firefox with NoScript. A script from best-deals-products.com was being blocked on every site that I went to (I never unblocked it so I can't confirm the statement about Firefox not being affected). It took me a while searching around to figure out it was the Superfish program. Rather than uninstall the program, I nuked the disk and installed the vanilla Windows from Microsoft.

I bought the Lenovo because I was really annoyed with Apple when my MBP died just after the 3 years of AppleCare I payed for expired on my 2011 model (notorious for failing: https://mbp2011.org/, I guess I can't win with laptop vendors). It was my first time working with OEM Windows in a while (laptop before the MBP was a Dell in 2005) and I was surprised at how much more bloatware vendors thought they could stuff into a new laptop compared to the past. Next time I guess I will either go back to Apple or get something that comes with Linux installed just to avoid the Windows bloatware.

Post reply on HN