Live data from Hacker News

Lenovo Caught Installing Adware on New Computers

thenextweb.com

351–360 of 435 posts

Re: Lenovo Caught Installing Adware on New Computers

#351

Earlier quoted context omitted.

It's a big company doing, so it's gonna be fine.

It's not just because they are a big company though. The "community", the industry and the government all share blame for the lack of liability for software. Edit: It's pretty bad form to downvote new accounts becuase you disagree. Imagine if I didn't know about hellbanning. Ask yourself what open source licenses, corporate EULAs and the NSAs defense have in common. The best hope here is that Lenovo explicitly promis…

[deleted]

Re: Lenovo Caught Installing Adware on New Computers

#352

Earlier quoted context omitted.

It's a big company doing, so it's gonna be fine.

It actually depends whether or not the practice is directly or indirectly agreed to by the user in the Terms of Use, Privacy Policy or similar document. Now, it's likely that users do agree to it, but if the language in their policies wasn't broad enough to cover action like this, theoretically it would be a violation of the Computer Fraud and Abuse Act, as exceeding authorized use.

This won't hold for Germany though. There is a concept of surprising clause (überraschende Klausel) as well as the concept of an unethical clause (sittenwidrige Klausel). In this case I would assume that both would hold even if there is some clause in the EULA. The BigCo argument holds in Germany unfortunately as well...

Re: Lenovo Caught Installing Adware on New Computers

#353

Earlier quoted context omitted.

If it wasn't intercepted from the cPanel then it may have been intercepted from the HTML file download from JSbin (which I copied into cPanel). Either way, this was a downloaded HTML file which was then copied into cPanel. I never viewed or edited the file between its download from JSbin & pasting into cPanel. The Malware was affecting files & not just pages viewed in browser. Nasty stuff.

It's much more likely that your web site or server was exploited directly, independent of you owning a Lenovo. This happens frequently; there are sophisticated operations out there scanning for a wide variety of ways into sites and servers. They pay special attention to shared hosting systems, which are not known for their high levels of security.

I don't think it was independent from the Lenovo issue.

See: http://superuser.com/questions/848853/what-is-best-deals-pro... http://stackoverflow.com/questions/27192298/can-not-open-a-p... http://forums.lenovo.com/t5/Lenovo-P-Y-and-Z-series/Lenovo-P... http://us.battle.net/wow/en/forum/topic/16283439126

The best deals script is the very same which I found on my machine, Lenovo is written all over this.

Re: Lenovo Caught Installing Adware on New Computers

#354

Jebus, how far the might IBM laptop line has fallen under the leadership of Lenovo. There was a time when a ThinkPad was arguably the best laptop money could buy. Many companies, including Google, would offer a choice between a ThinkPad or a MacBook, because those were the really reliable choices that were free of shovelware. I even considered buying a Lenovo recently when a pretty nice looking ThinkPad was on sale,…

Hell, who do we go with now? I'm a sys/web admin/devops by day and we just buy whatever is the hottest Lenovo, image them, and send them off for staff to use. They're rock solid from a hardware perspective and their laptops are usually top notch (ignoring the redesigned trackpad issues, they're pretty much perfect for business use).

We've tried HP and Dell in the past with the same ugly results. Horrible default images full of crapware, though not MITM bad. The only difference is that we had 10x the hardware issues with Dell and HP. We always need to make our own images. Windows OEM is a nightmare of shit crapware, which is a shame as the stock windows product is actually, dare I say, good? At least good for business use cases.

I also find it amusing that anytime there's some kind of issue in the US people instantly yell NSA, but thus far no one has thought to think this could be the CCP's attempt to spy on people by weakening SSL. I'm sure its trivial for them to grab the private key from Lenovo. Seems like the cyberwars are heating up.

Personally, I hope this becomes a major scandal. This deserves lots more press. In fact, every anti-virus product should remove this and the certificate. Anything short of that is irresponsible. This is congressional investigation worthy right here.

Re: Lenovo Caught Installing Adware on New Computers

#355
post #51

Earlier quoted context omitted.

I'm curious what legal stance Lenovo customers have here - their secure HTTPS connections are being MITMed intentionally - surely that's hacking, or some national security violation?

"National security" is such a fickle concept. You can bet that if the NSA manages to use this to hoover up some tasty HTTPS, this scandal will be lauded as a big boost to "national security" behind the scenes, and nobody will be punished. For all we know NSA had a hand in engineering this. Of course, if some government data is stolen as a result, then the whole thing will be thrown under the bus and deemed a threat t…

The employers that I know of who do government work require that all computers/phones work is performed on be of certain manufacturers which are US companies, an issue like this is the exact thing they cite as the reason for not using foreign companies as providers of such hardware. So the chance of government data being stolen is minimal, so the chance of the US government caring much is unlikely. So I doubt this will wind up under that bus.

Re: Lenovo Caught Installing Adware on New Computers

#356
post #86

Earlier quoted context omitted.

Microsoft itself has provided Windows installation media for download since Windows 8, including Windows 7 media. All you have to do is read your key off BIOS or the sticker. And of course Windows 10 will be a free download.

Free? I thought that was only if you already had 7 or 8 installed.

Yes, Windows 10 requires having 7 or 8. Still free.

Re: Lenovo Caught Installing Adware on New Computers

#357

Earlier quoted context omitted.

> Operations the size of Lenovo have a fairly intense vetting process before a product goes to market. How does that go along with a gigantic fuckup like this? Ipso facto there was no vetting, otherwise this wouldn't happen. What did they expect, that this wouldn't come out, that this wouldn't damage their brand even further? If it was done out of malice it is still poorly vetted and incompetent malice.

Just repeat, “Never ascribe to malice that which can adequately be explained by incompetence.” They probably didn't figure out that anyone would have a problem with this. For them, it's just a cool gimmick to get some money. That it is a gaping security hole which makes about 0.42 % of user population mad, probably never occurred to them. Unfortunately, for the 0.42 % (that is us, reading this site, and people of sim…

> Just repeat

Yea, read again. I claim that even if there was malice there necessarily was an element of incompetence present in that case as well.

> it will be hard going to explain to the next 4.2 % why this is so bad

Why? People aren't interested in exact details, that's why they rely on 0.42%. You can illustrate the magnitudes of moronity required to design some of their products and lack of respect for security by explaining that they approach those that are needed to drive a car which has chainsaw strapped on its steering wheel. This isn't mere buffer-overflows due to bad coding, these are comatose levels of stupidity.

Re: Lenovo Caught Installing Adware on New Computers

#358
post #283
post #51

Earlier quoted context omitted.

I'm curious what legal stance Lenovo customers have here - their secure HTTPS connections are being MITMed intentionally - surely that's hacking, or some national security violation?

It should absolutely be illegal to do something like this.

I think what you meant to say is that the existing laws that make something like this illegal should be enforceable in a meaningful way against large manufacturers and retailers.

Re: Lenovo Caught Installing Adware on New Computers

#359

Earlier quoted context omitted.

It's a big company doing, so it's gonna be fine.

It actually depends whether or not the practice is directly or indirectly agreed to by the user in the Terms of Use, Privacy Policy or similar document. Now, it's likely that users do agree to it, but if the language in their policies wasn't broad enough to cover action like this, theoretically it would be a violation of the Computer Fraud and Abuse Act, as exceeding authorized use.

Some EULAs basically say "you give permission for us to access and modify any data in your system"... this is the first example that comes to mind:

http://en.wikipedia.org/wiki/PunkBuster

These agreements could be summed up in 3 words: "we own you".

Re: Lenovo Caught Installing Adware on New Computers

#360

Just found this: Spy agencies ban Lenovo PCs on security concerns (27th July 2013) - http://www.afr.com/p/technology/spy_agencies_ban_lenovo_pcs_... "Multiple intelligence and defence sources in Britain and Australia confirmed there is a written ban on computers made by the Chinese company [Lenovo] being used in “classified” networks."

Right, I remember this and when the Huwai stuff came out. The typical anti-western loudmouths said it was protectionism. Now the very same loudmouths are back-peddling and assuring us that this was a simple oversight and there's no way any of this could ever be tied to the CCP. Its incredible how anything that happens in the US is a NSA plot but a fucking MITM shipped on millions of chinese laptops? Oh just a mistake from a junior dev, nothing to see here guys.

I sometimes wonder if autocratic regimes are so image focused that they've seeded popular forums with stooges.

Post reply on HN