Live data from Hacker News

Lenovo Caught Installing Adware on New Computers

thenextweb.com

341–350 of 435 posts

Re: Lenovo Caught Installing Adware on New Computers

#342

As a Lenovo owner, I'm really pissed off, and offended. I feel violated. I just can't comprehend how they could think they wouldn't get caught at something like this. Especially with the current climate of the privacy movement in the US. This is bad, very bad for Lenovo.

I just wanted to echo your sentiments. I bought my T440p last year and have otherwise been reasonably happy with it (though not entirely, due to the iffy trackpad). Fortunately the first thing I did was replace the hard drive. Despite that, I'll never buy another Lenovo product. I have completely lost confidence in the company.

Re: Lenovo Caught Installing Adware on New Computers

#343
post #86

Earlier quoted context omitted.

Microsoft itself has provided Windows installation media for download since Windows 8, including Windows 7 media. All you have to do is read your key off BIOS or the sticker. And of course Windows 10 will be a free download.

Unless things have changed, usually the sticker key is only valid for a certain kind of media. E.g. VLK's only work with VLK images, retail keys only work with retail images...

That's true, but in the past I've found that if I call Microsoft support and explain that I'm re-installing, they'll give me a new key over the phone.

Re: Lenovo Caught Installing Adware on New Computers

#344
post #285

Earlier quoted context omitted.

The issue here isn't so much the ads as it is being able to authenticate that the remote party is who you think it is – if your browser trusts the MITMed certificate, you no longer have the guarantee that your banking website is actually your banking website and nothing nefarious, as the page has been intercepted (maliciously or not) in-flight. avast! was actually guilty of this a while ago (see https://lelutin.ca/po…

if your browser trusts the MITMed certificate, you no longer have the guarantee that your banking website is actually your banking website and nothing nefarious, as the page has been intercepted (maliciously or not) in-flight. The trust essentially moves from the browser to the proxy - while I don't know what Superfish does, Proxomitron definitely checks the certificate and pops up a warning dialog if there's somethi…

Presumably (hopefully!) when you installed Proxomitron, it generated a new unique private key for your own personal MITM.

Apparently Superfish ships from Lenovo with the same private key on every machine. So all a bad guy needs to do is extract that private key from one machine, and now they can MITM all the Superfish Lenovo machines from basically anywhere on the Internet.

Re: Lenovo Caught Installing Adware on New Computers

#345
post #328
post #8

Earlier quoted context omitted.

Anyway to see if that certificate is on a Lenovo computer? Anyway to remove it? I bought a Lenovo laptop recently, and I was appalled at the amount of crapware that was installed. It's a wonderful laptop at a great price, just too bad about the software.

A cloudflare developer (I think) has put a test site up here: https://filippo.io/Badfish/ The idea is something like where haveproblem.gif is signed with the superfish cert (so you'll get an error if your machine does not have it, triggering the onError JS).

Here's the url:

https://badfish.filippo.io/yes.png

Re: Lenovo Caught Installing Adware on New Computers

#346
post #244

Earlier quoted context omitted.

I don't believe that. They would have to have some sort of software that is able to detect that you are connecting to cpanel and then act on your behalf. That is significantly more involved and more malicious than "just" intercepting html in flight and injecting adds.

If it wasn't intercepted from the cPanel then it may have been intercepted from the HTML file download from JSbin (which I copied into cPanel). Either way, this was a downloaded HTML file which was then copied into cPanel. I never viewed or edited the file between its download from JSbin & pasting into cPanel. The Malware was affecting files & not just pages viewed in browser. Nasty stuff.

It's much more likely that your web site or server was exploited directly, independent of you owning a Lenovo. This happens frequently; there are sophisticated operations out there scanning for a wide variety of ways into sites and servers. They pay special attention to shared hosting systems, which are not known for their high levels of security.

Re: Lenovo Caught Installing Adware on New Computers

#348
post #182

Hardware manufacturers cannot be trusted with software. One day the horrors of proprietary firmware will come to light as well, and people will wake up to this shit. Dells entire business line of Latitude laptops have been completely broken under Linux for 10 months. It took them that long to merely revert the "keyboard improvements" made between two BIOS revisions, but they subsequently shipped, and are still shippi…

People should also file complaints with their state consumer protection division. There are probably at least one or two AGs who would love to make an example out of Lenovo (big bad foreign company, etc.).

Here's the complaint form for Massachusetts: http://www.eform.ago.state.ma.us/ago_eforms/forms/piac_ecomp...

Re: Lenovo Caught Installing Adware on New Computers

#349

I'm surprised that this is just now news. I received complaints from people participating in our beta trial ( http://sketchtogether.com ) from as early as October 22nd, 2014 that our website was broken, and it was because of Superfish being installed on their lenovo laptops. When they uninstalled Superfish, our webpage started working again. Superfish injected a line of code that referenced "sf_main.jsp" from a remot…

` https://www.best-deals-products.com/' sounds like the classic online store that will steal your CC :-)

I wonder how many people would find the domain name suspicious - I instinctively felt "this sounds scammy to me" when I saw that name, but can't quite explain exactly to someone else how I got that feeling. Perhaps the keywords "best", "deal" and "product" raised the red flags for me, and it's an instinct acquired by many years of being online.

Re: Lenovo Caught Installing Adware on New Computers

#350

And it has been successfully cracked[1], revealing (potential) associations with a dodgy SSL redirector [2]. [1] http://blog.erratasec.com/2015/02/extracting-superfish-certi... [2] http://www.komodia.com

Also worth giving credit to ChuckMcM who was on the right track a few hours prior:

https://news.ycombinator.com/item?id=9072815

Post reply on HN