Live data from Hacker News

Lenovo Statement on Superfish

news.lenovo.com

101–110 of 312 posts

Re: Lenovo Statement on Superfish

#102
post #32

Earlier quoted context omitted.

Can you ever imagine Apple pulling a stunt like this? No, because it’s astonishingly user hostile: Lenovo should be hanging their head in shame, not making out like it’s no big deal.

The big difference is you don't mind when Apple does things like this. If you have "Hey, Siri" enabled then your phone's microphone is on all the time listening to everything you say. But I don't see a lot of people crying foul over that.

Well, there is a difference between "hey, we have this cool service you'd like but we need to process your voice data; maybe or maybe not we're doing something else with it" and "we're forcing ads down your throat and hey, now everyone can MITM you and rob your bank account clean".

Re: Lenovo Statement on Superfish

#103
post #3

Earlier quoted context omitted.

Anybody can MITM secure connections these computers make, right?

And present any HTTPS cert of their choosing to any compromised visitors e.g https://b4nk0famer1ca.com/

Hm... I'm pretty sure that if you can actually MITM their connection (i.e. you can intercept and modify the packages, e.g. by setting up a rogue Wi-Fi hotspot), you can also fake the DNS and/or IP addresses, so you shouldn't have a problem compromising visitors of https://bankofamerica.com.

Re: Lenovo Statement on Superfish

#104
"We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns."

One way to read this is they have not seen any evidence that people have actually been hacked in the wild. They may understand perfectly well that it is now trivial to do this but no one's actually reported yet that they had thousands of dollars stolen due to using online banking on a compromised Lenovo machine on public Wi-Fi.

Roll on the class action lawsuits.

Re: Lenovo Statement on Superfish

#105
I've been a ThinkPad customer for ages, and have recommended them to others many times. I'm fuming mad over this.

What's the best way to tell Lenovo they fucked up? I mean, I can vent over social media all day but will they even pay attention?

Re: Lenovo Statement on Superfish

#106
post #4

> We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns. I try to be measured around here, as hard as I can. I can't formulate a polite way to respond to this claim. Lenovo, you are full of shit, and maliciously so. There is no excuse, nor forgiveness, for what you've done here.

Well to be honest I've worked with OEM's before.

They are so big and bureaucratic, half the time they don't know who is working on what.

This behavior is still inexcusable.

Somebody should be fired for putting this garbage on computers to "enhance the users experience."

Re: Lenovo Statement on Superfish

#108
post #32

Earlier quoted context omitted.

Can you ever imagine Apple pulling a stunt like this? No, because it’s astonishingly user hostile: Lenovo should be hanging their head in shame, not making out like it’s no big deal.

The big difference is you don't mind when Apple does things like this. If you have "Hey, Siri" enabled then your phone's microphone is on all the time listening to everything you say. But I don't see a lot of people crying foul over that.

"Hey siri" is only enabled when your phone is plugged in, and it processes that particular phrase on device, not across a network.

Re: Lenovo Statement on Superfish

#109
post #95

Earlier quoted context omitted.

Not even a hint of an admission on the certificate issue, I'm not surprised. If they admit they knew about the root certificate or even acknowledge its existence after the discovery, they could open themselves up to legal liability if someone's bank account or identity is compromised. This really sucks because I used to recommend Lenovo workstations and ThinkPad laptops to people; it really is good hardware at a dece…

They actually reference the root certificate in their removal instructions: "Uninstalling Superfish Visual Discovery Go to Control Panel > Uninstall a Program Select Visual Discovery > Uninstall Superfish will be removed from Program Files and Program Data directories, files in user directory will stay intact for the privacy reason. Registry entry and root certificate will remain as well. The Superfish service will s…

So they're basically telling you how to get rid of ads and call it solved, while still leaving you vulnerable to getting robbed by any script kiddie that gets his hands on the certificate key?

Re: Lenovo Statement on Superfish

#110

Earlier quoted context omitted.

> supermarket special offers Why would you not want to sign up to know about what discounts are available at your local grocery store, especially if you frequent it weekly.

Keyword there is "snail mail." You're saying you really want this stuff in your mailbox every week? I don't want any snail mail(of any kind), any week but it's something I still have to live with.

In contrast, I've been refusing to opt-in to my banks online statements for a long time now, simply because I want to have important stuff (e.g. my money) printed black-on-white. Email can be easily faked.
Post reply on HN