Live data from Hacker News

Lenovo Caught Installing Adware on New Computers

thenextweb.com

331–340 of 435 posts

Re: Lenovo Caught Installing Adware on New Computers

#331

Earlier quoted context omitted.

For low-end machines these bundling deals likely form a sizeable chunk of the profit margin. (I've heard eyebrow-raising numbers for e.g. the default browser spot.)

Yep. The other chunk results from the OEM's refusal to stick to any long term consistency in the components they spec in consumer lines of devices. In business lines, you will likely get a 6-12 month guarantee with a 6-24mo forecast showing exactly what is shipping with what (CPUs, GPUs, screens, hard drives, etc). With consumer lines, they change components & suppliers any time, for any reason.

>With consumer lines, they change components & suppliers any time, for any reason.

I always love when the same model (down to the part number) comes with a different configuration and board inside the case.

Re: Lenovo Caught Installing Adware on New Computers

#332
post #95

Earlier quoted context omitted.

Is it even possible to buy a Windows laptop right now with only the OS installed? This is exactly why I've been recommending Chromebooks to anyone who asks my advice for about a year now.

> Is it even possible to buy a Windows laptop right now with only the OS installed? Microsoft's Windows Installation Media Creation Tool [1] enables you to download a clean Windows 8.1 ISO that can be used to re-install the operating system and wipe out all of the preloaded bloatware on any PC. To do the same with a Windows 7 PC, visit Microsoft's Software Recovery website [2]. From Windows 8.1 Update 1 onwards, ther…

Good list of resources, but I'd like to add that the Windows 7 recovery page doesn't accept OEM license keys. If you try to enter the key from the sticker on your laptop, you will most likely be told to contact your hardware provider. Which means you're stuck with their crapware installer.

Re: Lenovo Caught Installing Adware on New Computers

#333

Jebus, how far the might IBM laptop line has fallen under the leadership of Lenovo. There was a time when a ThinkPad was arguably the best laptop money could buy. Many companies, including Google, would offer a choice between a ThinkPad or a MacBook, because those were the really reliable choices that were free of shovelware. I even considered buying a Lenovo recently when a pretty nice looking ThinkPad was on sale,…

I've purchased two post-acquisition Lenovos. A Thinkpad X1 Carbon first gen and, when it was stolen, a second gen. Both are truly excellent laptops, perfectly on par with the Thinkpad R40 and the X61t I had before.

The second gen X1 Carbon has two "innovations" I could live without. A clickpad and an LCD serving as function row keys. I must not be alone in my woes, as the third gen X1 Carbon reverted the change and has normal trackpad buttons and real function keys.

Other than that, the same quality Thinkpad build. It's not a war tank as the R40 was but, then again, it does not have the weight constraints that allow for a rollcage.

I know it is fashionable to say Lenovo fumbled the Thinkpad brand but, at least in the top of the line products, this isn't true. Of course, this is anecdotal, based on my company's purchases and nothing else. If you listen in forums, the landscape is much as the one here on HN (even if 90% of those who speak never bought a "chinese" Thinkpad)

Re: Lenovo Caught Installing Adware on New Computers

#334
post #115
post #94

Earlier quoted context omitted.

but apparently no one did a security review It doesn't take a "security review" to spot a gaping security and privacy violation like this. Any engineer with even the slightest clue of how a browser and "the internet" works would have called this out during the first "How does this product work?"-presentation. Let's not pretend Lenovo is staffed with monkeys.

“Never ascribe to malice that which can adequately be explained by incompetence.” Remember stuff like this: http://www.cryptofails.com/post/70059600123/saltstack-rsa-e-... (Which, possibly unfairly, is one reason I'm leaning more towards ansible than saltstack to this day -- I mean, if stuff like that got through... what else, in more complex areas of the system?)

The problem in Lenovo's situation is, calling it incompetence is the real stretch. You could call Charles Manson incompetent saying he just didn't know what he was doing was wrong, but everyone knows he was just evil.

Never falsely attribute to incompetence what is actually ascribable to malice. You can't come in here with a straight face and say that no one at Lenovo considered the security risk of including this software. If it was considered and they pushed ahead with it anyway, that's malice.

Re: Lenovo Caught Installing Adware on New Computers

#336
post #5

This is much worse than just installing adware. They install a web proxy which MITMs all web connections, including HTTPS by means of a pre-installed trusted root certificate. The root certificate is the same across all installs, and the private key is present on the machine (necessarily, to operate the proxy): https://twitter.com/fugueish/status/568258997578371072 Someone will extract the private key in the next few…

>They install a web proxy which MITMs all web connections, including HTTPS by means of a pre-installed trusted root certificate. That's the odd part of this. Browser plugins can modify the DOM (insert ads, change search results, etc) without proxying anything. So why do it? I wonder if they were fishing for an NSA contract to further monetize the installs.

Browser plugins are easy to wipe out. When dealing with a rather persistent malware a few months ago, it had inserted a legacy policy for a proxy in the Windows registry in a place not commonly checked by malware scanners. You turn off the proxy settings, but at every reboot it would come back and nothing seemed to catch it at the time. Malware can inject things in to the local group policy and other places that are not commonly checked, such as the root cert store, making them very likely to be missed by tech support.

Re: Lenovo Caught Installing Adware on New Computers

#337
post #241

Earlier quoted context omitted.

But doesn't that defeat the purpose? If a trusted Chinese certificate authority issues some certificate on google.com for China to perform MITM attack, and Chrome ignores anything signed by a valid root certificate, it will never report this attack. I thought the point of certificate pinning is precisely that only a single authority can sign a certificate for a website.

No, the purpose of pinning is to stop a compromised CA from issuing their own www.google.com cert. If someone installs a CA, Chrome will trust it. There's not much way around this: if someone has the capability to install a CA on your computer, they'd have the capability to modify chrome.exe to force acceptance of it. Also, sometimes MITM'ing is desired. I'm doing it right now with Firefox and BurpSuite.

I think the problem is rather giving a false sentiment of security to the unsuspecting user.

Re: Lenovo Caught Installing Adware on New Computers

#338

Earlier quoted context omitted.

Not sure what you mean with "non-traditional keyboard", but Lenovo did change the keyboard in the 3rd generation Thinkpad X1 Carbons, reverting the layout of the 2nd generation to a more conventional one: with six rows instead of five. Glad they did. Ars Technica just reviewed the 3rd generation version: http://arstechnica.com/gadgets/2015/02/thinkpad-x1-carbon-re... .

As far as I am concerned this one has the non-traditional keyboard (CTRL is NOT in the lower left corner). Mess with my muscle-memory and you're sure I will never buy your laptop. Same reason I'll never consider MacBooks: Non-standard keyboard.

Oh man I hate keyboards like that. If the keyboard is causing me to hit wrong keys, it's the keyboard that's wrong.

Re: Lenovo Caught Installing Adware on New Computers

#339

Earlier quoted context omitted.

Not sure what you mean with "non-traditional keyboard", but Lenovo did change the keyboard in the 3rd generation Thinkpad X1 Carbons, reverting the layout of the 2nd generation to a more conventional one: with six rows instead of five. Glad they did. Ars Technica just reviewed the 3rd generation version: http://arstechnica.com/gadgets/2015/02/thinkpad-x1-carbon-re... .

As far as I am concerned this one has the non-traditional keyboard (CTRL is NOT in the lower left corner). Mess with my muscle-memory and you're sure I will never buy your laptop. Same reason I'll never consider MacBooks: Non-standard keyboard.

I used to feel the same until I remapped CapsLock to Insert on a MacBook running Linux so I could regain the ability to paste with Shift-Insert. After that I realized that none of my other keyboards had Insert in the same location, so having a non-standard keyboard wasn't unique to Apple. Now I try to remap certain keys on all my machines to the smallest set they share in common, so I can take my muscle memory with me.

Re: Lenovo Caught Installing Adware on New Computers

#340

Would it be correct to assume that this doesn't affect any of the thinkpads used at IBM?

If they've installed Windows themselves (as I suspect many enterprises have) it's probable, but I wouldn't say it's correct to assume. There's a test going I've seen being shared around by people who are fairly trusted in the tech community that uses an image (supposedly) signed with the private key to see if the certificate is installed: https://filippo.io/Badfish/. If I were you I'd at least check that out.
Post reply on HN