Live data from Hacker News

Lenovo Statement on Superfish

news.lenovo.com

121–130 of 312 posts

Re: Lenovo Statement on Superfish

#121
post #4

> We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns. I try to be measured around here, as hard as I can. I can't formulate a polite way to respond to this claim. Lenovo, you are full of shit, and maliciously so. There is no excuse, nor forgiveness, for what you've done here.

I think we just found out where Baghdad Bob works nowadays.

Re: Lenovo Statement on Superfish

#122
post #27

> The relationship with Superfish is not financially significant; our goal was to enhance the experience for users. I would prefer for this to be a lie than for it to turn out for this statement to be true. Surely nobody at Lenovo honestly belived that ad injection improved user experience?

This would SEEM obvious because as techies we hate ads. But you can't extrapolate this to the general population. There was one time when I visited my mother. We started her instant messaging program, and we were presented with special offers. I recognized it as such within half a second, so I almost automatically checked the 'Do not show this again' checkbox. My mother alarmed me: "No, do not make it go away! I want…

The flip side is that there are genuine discounts for many products that save you money with no strings attached. It's just differential pricing: they want to sell their products for more money to people who want to spend more money. Or it's part of an affiliate advertising program and the way to ensure affiliate codes get entered by buyers is to offer them a discount.

I hate many ads too but I'll seek out discounts when I think they might exist.

Re: Lenovo Statement on Superfish

#123
While this kind of foistware sucks, I'm also a bit dismayed by the seeming domain-specificity of peoples' privacy concerns.

Do a simple tracker on a desktop, and people freak out. But all you have to do is change the form factor and UI metaphor to mobile and people are absolutely fine with constant location tracking, ambient sound being uploaded to the cloud (SIRI, etc.), a camera and a microphone that can be activated by all kinds of apps while the device is in your pocket, and a constant 24/7 Internet connection. You could never even approach that level of invasiveness on a desktop or laptop.

A desktop/laptop is a computer. A smartphone is a computer. Why the different reaction?

I wonder if it's a generation gap thing. Older people tend to use mobile devices less than younger people. Are the younger generation this oblivious?

Same phenomenon holds by the way with regard to jailed devices. Way back when Microsoft tried to introduce something called "trusted computing," which was basically just code signing. Everyone flipped the hell out and they shelved it. But mobile devices can't run software that isn't tethered to their app stores, and everyone is totally fine with that. Different form factor, different universe?

It also seems related to brand. When you sign into Chrome with your Google ID, Google tracks everything you do. But that's Google, not some random little foistware company, so that's okay I guess. Same goes for Safari and iCloud, etc.

Re: Lenovo Statement on Superfish

#124
post #63

Earlier quoted context omitted.

> Surely nobody at Lenovo honestly belived that ad injection improved user experience? I can see the marketing folks honestly believing this. See, the problem with people in marketing is that they come up with ideas that sound good in theory but neglect to consider the implications. "Wouldn't it be great if I was presented with offers to buy things based on context clues in the web pages I'm browsing?" "Wouldn't it b…

I don't know. My experience with the output of marketing and sales people is that they come up with ideas that sound good only to them , and not to anyone with even a miligram of conscience. I try to attribute it to a kind of job-related blindness rather than malice, but seriously - quite often those ideas boil down to "how can we scam those poor schmucks"? It's like no one ever asks themselves the question if the id…

Well, at least in my experience they do come up with some ideas that are genuinely about making the user experience better (to increase retention/sales/etc. of course). Like the idea about doing away with or simplifying passwords somehow. It's an idea with good intentions and if it could work perfectly it would be _awesome_. But it doesn't work perfectly -- there are major drawbacks. The sales and marketing folks just don't understand that part of the equation.

Re: Lenovo Statement on Superfish

#125
post #32
post #4

> We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns. I try to be measured around here, as hard as I can. I can't formulate a polite way to respond to this claim. Lenovo, you are full of shit, and maliciously so. There is no excuse, nor forgiveness, for what you've done here.

Can you ever imagine Apple pulling a stunt like this? No, because it’s astonishingly user hostile: Lenovo should be hanging their head in shame, not making out like it’s no big deal.

Many companies exist in a reality distortion bubble where they think that by phrasing a feature in a certain way, it becomes less customer hostile.

Case in point; Lenovo pitched this as a "way for our customers to find new products". This is not a problem most users have, which is why the starting point for customer-centric design should ALWAYS be user feedback. This can be collected any number of ways (focus groups, surveys, etc.) but if you ask leading questions, you're going to get the answers you wanted to hear.

I don't doubt that the people who put this product together thought that it was an enhancement to the user experience. The problem is that they didn't do the research prior to even developing the project. So the end result is a product that solves only one problem: how can Lenovo get in on some sweet advertising dollars?

Re: Lenovo Statement on Superfish

#126
post #61
post #42

Earlier quoted context omitted.

> We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns. I work at a large Telco/ISP and I understand how this kind of thing happens (though I'm not excusing it). First they come to the tech people and we explain exactly what's going on. Our managers translate it so they can understand it, and push it up with their name on it. Those Directors translate it so th…

To be honest, it seems something coming out of PR/Lawyer guys rather than actual engineers. I mean, the statement is pretty clear and leaves little room for doubt, it would take a lot of simplification and misunderstanding to twist a proper technical analysis (provided it has been done, or even asked) to this level.

> I mean, the statement is pretty clear and leaves little room for doubt

That's how you know it isn't from an engineer. We always leave a little room for doubt e.g.

"I'm 90% sure this will work!"

Re: Lenovo Statement on Superfish

#127

Honestly, I wish there was a way to comment on their stupid statement. These bullsh*t companies need to realize that users don't want the stupid bloatware in the first place. I paid you a TON of money for this computer the least you can do is give it to me in its best condition. You wouldn't buy a car that came painted with advertisements on the side!

They are perfectly aware of how people feel about bloatware. Dell at one point offered clean installs but you had to pay something like $30 extra. This probably provides some type of clue that they make about that much more per machine by including all the pre-installed crap.

Re: Lenovo Statement on Superfish

#128
post #32
post #4

> We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns. I try to be measured around here, as hard as I can. I can't formulate a polite way to respond to this claim. Lenovo, you are full of shit, and maliciously so. There is no excuse, nor forgiveness, for what you've done here.

Can you ever imagine Apple pulling a stunt like this? No, because it’s astonishingly user hostile: Lenovo should be hanging their head in shame, not making out like it’s no big deal.

Apple does directly or indirectly hostile things to its users all the time.

Such as interoperability deficiencies, deleting competing apps from the store, etc.

Wake up.

Re: Lenovo Statement on Superfish

#129
post #4

> We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns. I try to be measured around here, as hard as I can. I can't formulate a polite way to respond to this claim. Lenovo, you are full of shit, and maliciously so. There is no excuse, nor forgiveness, for what you've done here.

Indeed. I have been buying IBM and then Lenovo Thinkpads for ages. I hate the thought that my next machine will be another brand. Lenovo: One customer lost. More to be lost.

If you re-installed your OS and didn't use the factory image (which always includes other bloatware), then you were not affected. Or if you installed another OS (Linux, BSD, etc) then you were not affected.

I love my thinkpad... but I've always paved over the factory image the moment I got my new laptop. This is egregious beyond a doubt, but it does not affect me so I'm not worried about buying more of their laptops.

Re: Lenovo Statement on Superfish

#130

Earlier quoted context omitted.

Indeed. I have been buying IBM and then Lenovo Thinkpads for ages. I hate the thought that my next machine will be another brand. Lenovo: One customer lost. More to be lost.

Why stop buying Thinkpads? Lenovo have acknowledged the issue and are now trying to resolve it. Everybody makes mistakes but how they fix those problems tells you a lot about the culture of the company. Lenovo also made a terrible mistake in removing the physical click buttons, but is now reintroducing them across their entire laptop range for 2015. What I see is a company willing to listen and admit their mistakes.…

As part of "fixing their mistake" Lenovo just outright lied about the security implications. So what does that tell you about them?
Post reply on HN