Live data from Hacker News

Lenovo Statement on Superfish

news.lenovo.com

91–100 of 312 posts

Re: Lenovo Statement on Superfish

#91
> Users are not tracked nor re-targeted

Have a look at code delivered by Superfish:

https://www.superfish.com/ws/sf_preloader.jsp

https://www.superfish.com/ws/sf_code.jsp

And grep for track and retarget. Just two snippets:

    var url = sfDomain + "trackSession.action?userid=" + similarproducts.b.qsObj.userid + "&sessionid=-10&action=ud_host_failed";
and:

    function isRetargetingEnabled(){
        if( similarproducts.b.enableRetargetingUnit && !isRetargetingBlackList()){
            return 1;
        } else{
            return 0;
        }
    }

Re: Lenovo Statement on Superfish

#92
post #32

Earlier quoted context omitted.

Can you ever imagine Apple pulling a stunt like this? No, because it’s astonishingly user hostile: Lenovo should be hanging their head in shame, not making out like it’s no big deal.

The big difference is you don't mind when Apple does things like this. If you have "Hey, Siri" enabled then your phone's microphone is on all the time listening to everything you say. But I don't see a lot of people crying foul over that.

If remember correctly their devices were sending back GPS coordinates to a server too?

Re: Lenovo Statement on Superfish

#93
post #4

> We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns. I try to be measured around here, as hard as I can. I can't formulate a polite way to respond to this claim. Lenovo, you are full of shit, and maliciously so. There is no excuse, nor forgiveness, for what you've done here.

I imagine Lenovo wants to tell you the truth but has the CCP's tank barrels pointed at their back. Further evidence that buying from autocratic regimes comes at a risk. I wouldn't run Kaspersky either, especially after Wired exposed their connections to the FSB and Russian military.

http://www.wired.com/2012/07/ff_kaspersky/all/

If this was going on with a US OEM, people would assume the NSA. But with Lenovo (which the US government refuses to buy btw) and Huwai and other non-vendors for the USG, HN'ers have regularly defended them and claimed the US was being paranoid or protectionist. How the hell do you think a fucking MITM gets onto a production image? This is financial suicide for Lenovo and they know it. This has all the telltale signs of government collusion. The CCP has a lot more to gain from stuff like this than Lenovo has to lose. How many people have been compromised from ship date until the day this gets uninstalled? Millions? For how many months? Years? That's a lot of SSL sniffing available to the CCP.

Re: Lenovo Statement on Superfish

#94
post #12
post #8

Lenovo is going to lose more through how they handle this than through the fact that they did it in the first place.

Sadly no. Businesses will still buy Thinkpads like candies.

Yeah and businesses run their own Windows images. Whatever software is preloaded doesn't matter.

Re: Lenovo Statement on Superfish

#95
post #2

"We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns." Seriously?!

Not even a hint of an admission on the certificate issue, I'm not surprised. If they admit they knew about the root certificate or even acknowledge its existence after the discovery, they could open themselves up to legal liability if someone's bank account or identity is compromised. This really sucks because I used to recommend Lenovo workstations and ThinkPad laptops to people; it really is good hardware at a dece…

They actually reference the root certificate in their removal instructions:

"Uninstalling Superfish Visual Discovery

    Go to Control Panel > Uninstall a Program

    Select Visual Discovery > Uninstall
Superfish will be removed from Program Files and Program Data directories, files in user directory will stay intact for the privacy reason. Registry entry and root certificate will remain as well. The Superfish service will stop working as soon as it is uninstalled via above process, and following reboot."

http://forums.lenovo.com/t5/Lenovo-P-Y-and-Z-series/Removal-...

Re: Lenovo Statement on Superfish

#96
post #63
post #27

> The relationship with Superfish is not financially significant; our goal was to enhance the experience for users. I would prefer for this to be a lie than for it to turn out for this statement to be true. Surely nobody at Lenovo honestly belived that ad injection improved user experience?

> Surely nobody at Lenovo honestly belived that ad injection improved user experience? I can see the marketing folks honestly believing this. See, the problem with people in marketing is that they come up with ideas that sound good in theory but neglect to consider the implications. "Wouldn't it be great if I was presented with offers to buy things based on context clues in the web pages I'm browsing?" "Wouldn't it b…

I don't know. My experience with the output of marketing and sales people is that they come up with ideas that sound good only to them, and not to anyone with even a miligram of conscience. I try to attribute it to a kind of job-related blindness rather than malice, but seriously - quite often those ideas boil down to "how can we scam those poor schmucks"? It's like no one ever asks themselves the question if the idea is actually good for the end user.

Good business is about providing value for proper compensation. If you're trying to trick your customer into paying more money for less value, you're just scamming them.

Re: Lenovo Statement on Superfish

#97
post #32
post #4

> We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns. I try to be measured around here, as hard as I can. I can't formulate a polite way to respond to this claim. Lenovo, you are full of shit, and maliciously so. There is no excuse, nor forgiveness, for what you've done here.

Can you ever imagine Apple pulling a stunt like this? No, because it’s astonishingly user hostile: Lenovo should be hanging their head in shame, not making out like it’s no big deal.

[deleted]

Re: Lenovo Statement on Superfish

#98
post #32
post #4

> We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns. I try to be measured around here, as hard as I can. I can't formulate a polite way to respond to this claim. Lenovo, you are full of shit, and maliciously so. There is no excuse, nor forgiveness, for what you've done here.

Can you ever imagine Apple pulling a stunt like this? No, because it’s astonishingly user hostile: Lenovo should be hanging their head in shame, not making out like it’s no big deal.

Tell me about it! Apple is user hostile in much more subtle ways.

Re: Lenovo Statement on Superfish

#99
post #86

Earlier quoted context omitted.

The big difference is you don't mind when Apple does things like this. If you have "Hey, Siri" enabled then your phone's microphone is on all the time listening to everything you say. But I don't see a lot of people crying foul over that.

The difference being that only Apple (and the us gov) can listen in, not the entire world.

Huh? How so?

Re: Lenovo Statement on Superfish

#100
post #51

Microsoft seems to have a vice like grip over OEM's regarding preloading windows on every product they sell without exception, IMHO this is a terrible thing, but can't they do at least a little good and prevent OEM's from shipping anything other than a pristine image with no preloaded software? Surely the endless bundled crapware from every OEM just gives Windows a bad reputation in the long term. The popularity of c…

No, they can't. The key crime in the antitrust trial was Microsoft preventing OEMs from installing additional software (Netscape).
Post reply on HN