Live data from Hacker News

Lenovo Caught Installing Adware on New Computers

thenextweb.com

361–370 of 435 posts

Re: Lenovo Caught Installing Adware on New Computers

#361
post #95

Earlier quoted context omitted.

Is it even possible to buy a Windows laptop right now with only the OS installed? This is exactly why I've been recommending Chromebooks to anyone who asks my advice for about a year now.

Yes it is, you can even buy laptops with no OS pre-installed or a gnu/linux distro. Chromebooks are the worst possible thing, I tell everyone to stay away from these crippled google branded piece of slavery. I advise either a second hand quality laptop or a brand new one while budgeting a little extra for cleaning the crap that manufacturers preload inside to allow for such a low selling price.

Chromebooks are great. I've recommended them to at least a dozen people by now and they are all super happy with them. And free from MITM!

Re: Lenovo Caught Installing Adware on New Computers

#362
post #133
post #95

Earlier quoted context omitted.

Is it even possible to buy a Windows laptop right now with only the OS installed? This is exactly why I've been recommending Chromebooks to anyone who asks my advice for about a year now.

You can buy "Microsoft Signature" machines from the MS stores and online. Hopefully the words will spread.

An unfucked machine is the superspecial case, something to boast about. Let that sink for a moment.

Re: Lenovo Caught Installing Adware on New Computers

#364
post #5

This is much worse than just installing adware. They install a web proxy which MITMs all web connections, including HTTPS by means of a pre-installed trusted root certificate. The root certificate is the same across all installs, and the private key is present on the machine (necessarily, to operate the proxy): https://twitter.com/fugueish/status/568258997578371072 Someone will extract the private key in the next few…

Aaaand here it is: http://blog.erratasec.com/2015/02/extracting-superfish-certi...

Re: Lenovo Caught Installing Adware on New Computers

#367

Earlier quoted context omitted.

It actually depends whether or not the practice is directly or indirectly agreed to by the user in the Terms of Use, Privacy Policy or similar document. Now, it's likely that users do agree to it, but if the language in their policies wasn't broad enough to cover action like this, theoretically it would be a violation of the Computer Fraud and Abuse Act, as exceeding authorized use.

Some EULAs basically say "you give permission for us to access and modify any data in your system"... this is the first example that comes to mind: http://en.wikipedia.org/wiki/PunkBuster These agreements could be summed up in 3 words: "we own you".

At least PunkBuster is spying for a relatively noble purpose: preventing cheating in online games. Cheating absolutely destroys the experience in multiplayer games and has killed many games.

This is spying with the sole purpose of spreading ads and making money.

Re: Lenovo Caught Installing Adware on New Computers

#368

Earlier quoted context omitted.

Not sure what you mean with "non-traditional keyboard", but Lenovo did change the keyboard in the 3rd generation Thinkpad X1 Carbons, reverting the layout of the 2nd generation to a more conventional one: with six rows instead of five. Glad they did. Ars Technica just reviewed the 3rd generation version: http://arstechnica.com/gadgets/2015/02/thinkpad-x1-carbon-re... .

As far as I am concerned this one has the non-traditional keyboard (CTRL is NOT in the lower left corner). Mess with my muscle-memory and you're sure I will never buy your laptop. Same reason I'll never consider MacBooks: Non-standard keyboard.

In the BIOS for most Thinkpads I've used recently there is a setting to swap the Fn and Ctrl keys.

Re: Lenovo Caught Installing Adware on New Computers

#369

Jebus, how far the might IBM laptop line has fallen under the leadership of Lenovo. There was a time when a ThinkPad was arguably the best laptop money could buy. Many companies, including Google, would offer a choice between a ThinkPad or a MacBook, because those were the really reliable choices that were free of shovelware. I even considered buying a Lenovo recently when a pretty nice looking ThinkPad was on sale,…

I can attest that thinkpad quality is on the decline, linux support too (not mentioning the stupidity of experimenting with new ways of doing keyboards[1]) but it's not that bad yet. Hardware is good, in case of trouble on-site warranty works well (once you've learned your way through the ibm website). Be informed about what you buy, skip the comically broken models (see adaptive keyboard) use common sense and your t…

Lenovo has learnt from that mistake though, the X1 Carbon Gen 3 basically has the keyboard from the Gen1 paired with the build quality and high quality IPS screen from the second gen.

Re: Lenovo Caught Installing Adware on New Computers

#370

Earlier quoted context omitted.

If it wasn't intercepted from the cPanel then it may have been intercepted from the HTML file download from JSbin (which I copied into cPanel). Either way, this was a downloaded HTML file which was then copied into cPanel. I never viewed or edited the file between its download from JSbin & pasting into cPanel. The Malware was affecting files & not just pages viewed in browser. Nasty stuff.

It's much more likely that your web site or server was exploited directly, independent of you owning a Lenovo. This happens frequently; there are sophisticated operations out there scanning for a wide variety of ways into sites and servers. They pay special attention to shared hosting systems, which are not known for their high levels of security.

As soon as he mentioned cPanel that was my assumption. A lot of the control panels are vulnerable in the default install and difficult to secure adequately. Don't get me started on database control panels, I regard phpmyadmin as malware that happens to use uneducated admins as the infection vector.
Post reply on HN