Live data from Hacker News

Lenovo Caught Installing Adware on New Computers

thenextweb.com

321–330 of 435 posts

Re: Lenovo Caught Installing Adware on New Computers

#321

Earlier quoted context omitted.

Just recently installed Windows 7 Pro on a HP ProBook thing: - looked up the Windows and Office license keys of the existing installation, using an utility - download Windows 7 disk image from Microsoft and burn on a DVD - take out the old disk with recovery partitions and installation with crappy bloatware - put in a new SSD disk, boot DVD to install OS and install Office - download and install HP specific drivers f…

I did the same, worked flawlessly. The only PITA was to put the ISO image on an USB stick.

It shouldn't be. You either use the "Media Creation Tool" which also can download the ISO or you the "Windows USB/DVD Download Tool".

http://windows.microsoft.com/en-us/windows-8/create-reset-re... http://wudt.codeplex.com/

Re: Lenovo Caught Installing Adware on New Computers

#322

Earlier quoted context omitted.

> Operations the size of Lenovo have a fairly intense vetting process before a product goes to market. How does that go along with a gigantic fuckup like this? Ipso facto there was no vetting, otherwise this wouldn't happen. What did they expect, that this wouldn't come out, that this wouldn't damage their brand even further? If it was done out of malice it is still poorly vetted and incompetent malice.

Just repeat, “Never ascribe to malice that which can adequately be explained by incompetence.” They probably didn't figure out that anyone would have a problem with this. For them, it's just a cool gimmick to get some money. That it is a gaping security hole which makes about 0.42 % of user population mad, probably never occurred to them. Unfortunately, for the 0.42 % (that is us, reading this site, and people of sim…

Hopefully we .42 will inform our fellow 4.2ers when they come to us for advice when buying a new laptop/anything Lenovo makes. I don't think it will be so hard to explain it to them. They already know what adware is. Just mention it comes installed ready to track you. Always listening while you're visiting bank.com.

Re: Lenovo Caught Installing Adware on New Computers

#323
post #241
post #189

Earlier quoted context omitted.

Chrome ignores Trusted Root Certificates when checking certificate pinning.

But doesn't that defeat the purpose? If a trusted Chinese certificate authority issues some certificate on google.com for China to perform MITM attack, and Chrome ignores anything signed by a valid root certificate, it will never report this attack. I thought the point of certificate pinning is precisely that only a single authority can sign a certificate for a website.

No, the purpose of pinning is to stop a compromised CA from issuing their own www.google.com cert.

If someone installs a CA, Chrome will trust it. There's not much way around this: if someone has the capability to install a CA on your computer, they'd have the capability to modify chrome.exe to force acceptance of it.

Also, sometimes MITM'ing is desired. I'm doing it right now with Firefox and BurpSuite.

Re: Lenovo Caught Installing Adware on New Computers

#324
post #297
post #272

Earlier quoted context omitted.

Incompetance probably. They didn't realise that it would be that much of a bad thing.

Hanlon's razor: Never attribute to malice that which is adequately explained by stupidity. ... I wonder if there's an MBA / capitalism version of this, centering around short-term profit at the expense of everything else.

Jumping at short-term profit over the people who trusted you is malice, in my book. Profit-uber-alles is not some thing that appears out of the ether--somebody has to do it.

Re: Lenovo Caught Installing Adware on New Computers

#325
post #213
post #162

Earlier quoted context omitted.

I'm not sure why anyone buys anything other than a home when accounting for resale value unless they're just trying to pull a pump-and-dump. For laptops, at least, I buy them and use them until they die. I've only owned three laptops in my life.

For a long time a 3-year-old laptop struggled to run the latest eclipse (this may well still be the case). So at that point I'll sell them on to someone with a less intense workload and buy a replacement.

> a 3-year-old laptop struggled to run the latest eclipse

There's a whole world of bad software engineering in that observation!

Re: Lenovo Caught Installing Adware on New Computers

#326

Earlier quoted context omitted.

Isn't superfish (or is it Phish?) a US/Israeli company? Some of the code inserted is pretty strange, including functions to checks for lenevo, bestbuy.com and isPayingCountry() with a list of country identifiers: http://pastebin.com/AQqWirba So apparently they work with some big companies, and I can't work out what the country check is for, perhaps for subsidiaries of a large customer?

The code you linked is nothing out of the ordinary as far as adware in Chrome plug-ins etc. go. For an example have a look at the source code[1] of "Awesome Screenshot"[2] which is used by ~1,4M users and also calls home to 7 different hosts[3]. This is just one of many many Chrome plug-ins that is injecting ads and Google encourages this[4]. It makes sense to limit injections to markets they can serve / are affiliat…

have a look at the source code[1] of "Awesome Screenshot"[2] which is used by ~1,4M users and also calls home to 7 different hosts

Insanity!

Re: Lenovo Caught Installing Adware on New Computers

#327
post #240

I used a ThinkPad 700 in 1992 and have bought ThinkPads ever since. Lenovo keep trying to ruin them while ignoring customers telling them to stop. A ThinkPad 1. Is robust 2. Is reliable 3. Is black 4. Has only useful software pre-installed, from the manufacturer (e.g. the Lenovo thing which updates drivers) 5. Has a TrackPoint 6. Has a consistent keyboard layout 7. Has hardware buttons ('mouse', function keys, etc.)…

Agreed. Somebody really needs to start making Thinkpads again. Lenovo ain't it. All they've done is manage to kill the brand.

They could rescue it easily, but they're muddled up between their (best selling, I presume) consumer (including low-end business) and premium business hardware.

If I was given the job of fixing this at Lenovo, I'd do this:

1. Kill off the ThinkPad brand. It's tainted.

2. Invent a new name for the premium laptops. Something workmanlike, off the top of my head: WorkStead.

3. Tell the world that the premium business laptops are now called WorkStead.

4. Tell the world what makes a WorkStead laptop, guaranteeing those things which have been broken repeatedly over the past few years, e.g. consistent keyboard layout, real buttons for everything.

4. Rebrand the X and T series with this name, but only the ones that deserve it.

5. Wait for people to again start saying 'Get me a fully loaded WorkStead T4xx series' like they used to do with ThinkPads, before they had to say 'Let me check which models they've managed not to ruin recently'.

6. Stop asking people to choose between 3 slightly different Intel wifi cards within $10 of each other in price, defaulting to the worst one, when they're buying a $3000 laptop.

... And other brokenness in the configurators.

Re: Lenovo Caught Installing Adware on New Computers

#328
post #8
post #5

This is much worse than just installing adware. They install a web proxy which MITMs all web connections, including HTTPS by means of a pre-installed trusted root certificate. The root certificate is the same across all installs, and the private key is present on the machine (necessarily, to operate the proxy): https://twitter.com/fugueish/status/568258997578371072 Someone will extract the private key in the next few…

Anyway to see if that certificate is on a Lenovo computer? Anyway to remove it? I bought a Lenovo laptop recently, and I was appalled at the amount of crapware that was installed. It's a wonderful laptop at a great price, just too bad about the software.

A cloudflare developer (I think) has put a test site up here:

https://filippo.io/Badfish/

The idea is something like

  
where haveproblem.gif is signed with the superfish cert (so you'll get an error if your machine does not have it, triggering the onError JS).

Re: Lenovo Caught Installing Adware on New Computers

#329

Earlier quoted context omitted.

The NSA doesn't need this amateur-hour backdoor. They surely have control of one or more genuine certificate authorities already.

Impersonating a CA is not transparent and risks losing that CA if anyone finds out it's forging certs. They probably can do that, but it's a risky nuclear option. This is a transparent dragnet that can easily be blamed away, which has been shown to be much more preferable in the NSA's M.O.

The sad thing is we don't need to invoke the big bad NSA here. There is absolutely positively nothing about this that suggests it is anything other than bog-standard SSL incompetence.

And to be clear, I mean, absolutely nothing. This isn't a slightly unlikely thing that still leaves room to wonder about "plausible deniability"... this is a thing that happens all the damned time and the NSA need at most sit back and passively reap the benefits, along with hackers and criminals.

Somebody somewhere wanted to get in on the advertising gig because it looks like free money. Their first attempt didn't work on HTTPS sites. Some techie was ordered to fix it. Said techie read a few things on a few sites and typed in the magic commands to "make it work" and probably literally didn't even know that they'd just annihilated security for all their users... they literally just knew that this made their software "work", and for them, pretty much the first time they clicked on to an HTTPS page and saw their own ads, the story ended. Ship it.

To a first approximation, nobody using SSL in some manner understands SSL.

Re: Lenovo Caught Installing Adware on New Computers

#330
post #51

Earlier quoted context omitted.

I'm curious what legal stance Lenovo customers have here - their secure HTTPS connections are being MITMed intentionally - surely that's hacking, or some national security violation?

It's a big company doing, so it's gonna be fine.

"Adware is malware with a legal team"
Post reply on HN