Live data from Hacker News

Lenovo Caught Installing Adware on New Computers

thenextweb.com

271–280 of 435 posts

Re: Lenovo Caught Installing Adware on New Computers

#271
post #248

Earlier quoted context omitted.

Mozilla has its own proxy settings as well, independent of Windows Control Panel configuration, so a Firefox user appears not to be impacted by the whole thing at all.

It's not clear to me. Just a few minutes ago (and after your post) this appeared on mozilla discussion forum given by [1] above (will come back to credit this- didn't copy and don't remember (and can't see!)). https://bugzilla.mozilla.org/show_bug.cgi?id=1134506 Down around 0200 PST 2015-02-19 EDIT: credit [1] cpeterso https://news.ycombinator.com/item?id=9072642

OK, so they might have added also a Firefox plugin that infects the Mozilla trusted CA list as well.

I guess Firefox should block that plugin as malicious.

Re: Lenovo Caught Installing Adware on New Computers

#272
post #5

This is much worse than just installing adware. They install a web proxy which MITMs all web connections, including HTTPS by means of a pre-installed trusted root certificate. The root certificate is the same across all installs, and the private key is present on the machine (necessarily, to operate the proxy): https://twitter.com/fugueish/status/568258997578371072 Someone will extract the private key in the next few…

Wow, there are tons of images on twitter about this [1]. There is one where they MITM https://www.bankofamerica.com/ too [2]. Why the hell would they do this. Brutal. [1] https://twitter.com/search?q=%23superfish&src=typd [2] https://twitter.com/kennwhite/status/568270748638318593/phot...

Incompetance probably. They didn't realise that it would be that much of a bad thing.

Re: Lenovo Caught Installing Adware on New Computers

#273
post #173

As a non-technical user with a newish Lenovo laptop, is there some way I can make sure I'm not affected by this?

Learn how to view a certificate in Chrome or Internet Explorer:

https://support.google.com/chrome/answer/95617?hl=en

Then look to see if the certificate for a secured site lists Superfish:

https://twitter.com/kennwhite/status/568270748638318593/phot...

(That doesn't prove it isn't on your computer, but it will show if it is actively intercepting your connections)

Re: Lenovo Caught Installing Adware on New Computers

#274

Jebus, how far the might IBM laptop line has fallen under the leadership of Lenovo. There was a time when a ThinkPad was arguably the best laptop money could buy. Many companies, including Google, would offer a choice between a ThinkPad or a MacBook, because those were the really reliable choices that were free of shovelware. I even considered buying a Lenovo recently when a pretty nice looking ThinkPad was on sale,…

I'll add I've witnessed bad mechanical design from Lenovo.

A friend bought a $1000 laptop (U330 touch) from them and a piece of plastic holding a hinge broke. When I looked at it, it was clear that the part could have been 10 times (yes, 10) thicker without adding much weight (about a gram I guess) and probably zero cost.

I find this mistake nearly unacceptable but the evil part comes when you ask for warranty and they tell you that you must have done something wrong, why would a hinge break otherwise? And you accepted the warranty terms, so its their right to say so.

Quality control also was an issue as the laptop first came with a malfunctioning keyboard and a non operating touch screen.

So yeah, now is not a good time to buy anything from Lenovo.

Re: Lenovo Caught Installing Adware on New Computers

#275

Earlier quoted context omitted.

WHAT THE ACTUAL FUCK. Never buying Lenovo again.

You can just get precise Windows version that was installed and format all the drives (including recovery) and then do clean install. Result: no bloat and no malware

No, no, no!

We can't just dismiss this sort of behavior because you can reformat the computer and "Result: no bloat and no malware". They need to learn that people won't let them get away with this. So no this is unacceptable, I too will never buy nor recommend a Lenovo product in the foreseeable future!

Re: Lenovo Caught Installing Adware on New Computers

#276
post #260
post #229

Earlier quoted context omitted.

I used the XPS 13 as my main machine from 2013 to late 2014 (when I switched to a MBPr). It was a nice machine initially but I found that it ended up looking pretty tattered (particularly the plastic edge, which looks and feels cheap and a bit fragile in the long run). Most annoyingly, it had a tendency to overheat, particularly when dual booting into Ubuntu. After about 20 minutes, I couldn't leave the thing on my k…

Yeah, I just can't stomach the thought of paying more for something where Linux isn't officially supported, so not only do I pay more, but have to deal with getting rid of MacOS and installing Linux. I can't stand the lack of focus follows mouse in MacOS X and a lot of the other little things I'm used to in Linux.

I've used both Bootcamp and Fusion for running Windows 8 and 7 (client insisted on using some Excel files, and some of the plugins only worked on Windows Excel...) and found both really quite pain free. In fact, whenever I can't get away with OpenOffice, I just use Fusion/Excel as a standalone app.

In fact Fusion on the MBPr was the first VM app I used that didn't suck; I used to run various VMs in VirtualBox on the XPS which had, in theory, the same specs and a better CPU and the lag was worse than ssh into a server on the other side of the world (not to mention the overheating)...

I hear you on moving away from Linux. You do get a feel, often, that OSX is consumer oriented and just "gets in the way". On the upside, when you need stuff, you can usually find it quickly and it just "works". That's the ecosystem. Still, if I was to go back, it would STILL be on a mac. One of my former colleagues wiped OSX and installed http://nixos.org/, so I'm sure a more popular distro would work out.

The thing is, well, this will sound like every other Apple addict out there, but, the hardware quality really makes a difference, and it is quite hard to explain. The MBPr is the first machine I've ever used that feels "perfect", as if they got everything right. And with most of my work done on the cloud anyway, I didn't need absolute top line specs; portability and things like battery life mattered more. Amongst the other machines in the house is an X230, which I wanted to get and boost instead of the XPS, but it feels almost ten years older.

As for price, in early 2014 I spent a few weeks looking for a good standard dev laptop for the company (which I've since left) and got a good feel for the alternatives. In raw specs, you can get a cheaper "laptop", something that will fit a backpack and work for a while unplugged, yes (think W530). If you need portability though, all ultrabooks at the time were more expensive if specced to the same level. We did buy a couple W530s and upgraded them a bit (32GB RAM, etc.) and all their users ended up using them like desktops. I do not know if this is still the case, probably not, but I've seen many nominally more powerful "ultrabooks" (like the YogaPad, whose user assured me he had better resolution than me) fail in other ways; battery life is one, creaky joints is another. It took me a few more months before I got over my psychological block and got the base spec MBPr when it came out in August... One thing to note is that there are corporate discounts; if you or your friends are employed by a big corp, you can save a few hundred. Also, the upgrades are REALLY expensive compared to alternatives - why pay 300 dollars for extra SSD when you can get an SSD-grade, flush-with-the-side card from Transcend on Amazon for under 50?

Re: Lenovo Caught Installing Adware on New Computers

#277
post #142

Earlier quoted context omitted.

Operations the size of Lenovo have a fairly intense vetting process before a product goes to market. I find it very hard to believe that no red flags were raised by any of the engineers, managers and especially lawyers who must have screened this "feature" for problems. It seems more plausible that the problem was known from the beginning (it is by design after all) and Lenovo decided to risk it.

> Operations the size of Lenovo have a fairly intense vetting process before a product goes to market. How does that go along with a gigantic fuckup like this? Ipso facto there was no vetting, otherwise this wouldn't happen. What did they expect, that this wouldn't come out, that this wouldn't damage their brand even further? If it was done out of malice it is still poorly vetted and incompetent malice.

Just repeat, “Never ascribe to malice that which can adequately be explained by incompetence.”

They probably didn't figure out that anyone would have a problem with this. For them, it's just a cool gimmick to get some money. That it is a gaping security hole which makes about 0.42 % of user population mad, probably never occurred to them.

Unfortunately, for the 0.42 % (that is us, reading this site, and people of similar interests) it will be hard going to explain to the next 4.2 % why this is so bad. The remaining approximately 96 % of population will stay largely uninterested.

Re: Lenovo Caught Installing Adware on New Computers

#278
post #142

Earlier quoted context omitted.

You're so optimistic it hurts "Any engineer" means something in HN, but we're not talking about "people who read HN" levels of engineer here, don't be mistaken. Some people that have had no or limited experience with software are assigned to software projects, and that's the issue with companies like Lenovo.

Operations the size of Lenovo have a fairly intense vetting process before a product goes to market. I find it very hard to believe that no red flags were raised by any of the engineers, managers and especially lawyers who must have screened this "feature" for problems. It seems more plausible that the problem was known from the beginning (it is by design after all) and Lenovo decided to risk it.

My own experience makes me suspect the same thing. I used to work for a company that was, at the time, trying to develop a privacy-enhancing product (ironically enough...) which did something somewhat similar (although not on the size of this fuckup -- they'd be intercepting, but not tampering with, encrypted traffic, and storing encrypted private data).

Virtually everyone in the engineering team raised a flag when the imbec...uhm, the Product Manager came up with the idea. We pointed out that a) this burdens us with the responsibility of storing sensitive data which can, at least, have significant legal implications and that b) even if it's encrypted data, it may be a little hard to market a privacy device that works by uploading user data to our server as a first step without being transparent about the whole process. Oh, and c) that the data recovery mechanism he proposed (which involved storing the users' private keys on our servers as well, just in case they lost their precious little gimmick) was, in this case, entirely retarded.

The whole thing didn't even make it to Legal, because everyone in the decision tree just thought that since there's no plaintext data being stored, there's no potential for a lawsuit (and when we told the PM about Lavabit, he came back two hours later saying he Googled it and that we're covered since we're not an e-mail provider). The bright heads in Marketing weren't exactly sure about the whole transparency thing. They thought we should keep it simple and just tell people that their data is safely encrypted and be done with it, because end-users don't need to know about tech mumbo-jumbo like encryption keys and all that.

I don't work there anymore (thank God) and they haven't launched in the meantime, but when I left, they were basically working on implementing this clusterfuck.

I'm sorry I can't be more specific than this (for obvious reasons, I hope). The point is, however, that decisions as complex as these (there's a stack of paperwork thicker than the Osbourne-1 involved in preloading anything on a laptop) are made through an elaborate process, not made "by mistake".

Someone knew there was a problem. The problem may have ended up misunderstood or washed out along the decision chain (although I find that fairly unlikely), but someone, at some point, decided this was ok.

Re: Lenovo Caught Installing Adware on New Computers

#279

I'm surprised that this is just now news. I received complaints from people participating in our beta trial ( http://sketchtogether.com ) from as early as October 22nd, 2014 that our website was broken, and it was because of Superfish being installed on their lenovo laptops. When they uninstalled Superfish, our webpage started working again. Superfish injected a line of code that referenced "sf_main.jsp" from a remot…

> (I assume the linked code is not copyrighted, if it is, please let me know and I can take it down).

it probably is, but by the look of things one can safely assume that they can fuck off

Re: Lenovo Caught Installing Adware on New Computers

#280

I quite like my new Lenovo M73 "Tiny" desktop [1]. It's fast and silent and really is tiny. But as far as adware/malware is concerned, that's a non-issue for me as the first thing I did when I got the machine was to replace the Windows drive with an Ubuntu SSD. [1] http://shopap.lenovo.com/au/en/desktops/thinkcentre/tinys/m7...

I replace my laptop OS with linux too but I don't want to financially contribute to companies that pull shit like this. Lenovo isn't going to change their practice unless sales take a hit or get into a legal mess. I'll personally will not buy anymore Lenovo hardware, and those new dell xps laptops look pretty nice anyway.
Post reply on HN