Live data from Hacker News

Lenovo Statement on Superfish

news.lenovo.com

131–140 of 312 posts

Re: Lenovo Statement on Superfish

#131

Earlier quoted context omitted.

Indeed. I have been buying IBM and then Lenovo Thinkpads for ages. I hate the thought that my next machine will be another brand. Lenovo: One customer lost. More to be lost.

Why stop buying Thinkpads? Lenovo have acknowledged the issue and are now trying to resolve it. Everybody makes mistakes but how they fix those problems tells you a lot about the culture of the company. Lenovo also made a terrible mistake in removing the physical click buttons, but is now reintroducing them across their entire laptop range for 2015. What I see is a company willing to listen and admit their mistakes.…

If I'm reading you correctly, you're making the argument that Lenovo, the company that was just discovered to have been intentionally shipping a massive security vulnerability on their laptops, is still thought of by you as listening to their users better than Apple, the company that would never in their wildest dreams even remotely consider the idea of putting something like Superfish on their computers, simply because Lenovo changed their minds and stopped shipping the security vulnerability?

"Oh, no, my husband's a good man. He even promised to stop beating me!"

Re: Lenovo Statement on Superfish

#132
post #124

Earlier quoted context omitted.

I don't know. My experience with the output of marketing and sales people is that they come up with ideas that sound good only to them , and not to anyone with even a miligram of conscience. I try to attribute it to a kind of job-related blindness rather than malice, but seriously - quite often those ideas boil down to "how can we scam those poor schmucks"? It's like no one ever asks themselves the question if the id…

Well, at least in my experience they do come up with some ideas that are genuinely about making the user experience better (to increase retention/sales/etc. of course). Like the idea about doing away with or simplifying passwords somehow. It's an idea with good intentions and if it could work perfectly it would be _awesome_. But it doesn't work perfectly -- there are major drawbacks. The sales and marketing folks jus…

I don't mind that kind of mistakes that much. Well, they don't understand the security implications, maybe they didn't listen to someone when they should have. Yes, sometimes it's a fuckup, but intentions were at least honest. As strongly as I hate scumbag marketers and sales, I strongly (and publicly) applaud those who have good intentions and are aiming for a win-win.

But here, in this particular case, you clearly have bad intentions with a side order of criminal negligence.

Re: Lenovo Statement on Superfish

#133
post #51

Microsoft seems to have a vice like grip over OEM's regarding preloading windows on every product they sell without exception, IMHO this is a terrible thing, but can't they do at least a little good and prevent OEM's from shipping anything other than a pristine image with no preloaded software? Surely the endless bundled crapware from every OEM just gives Windows a bad reputation in the long term. The popularity of c…

Perhaps Microsoft could put out a security update to remove any Superfish certificates left. Still after the fact, but better than doing nothing (and leaving these suspicious certs around).

Re: Lenovo Statement on Superfish

#134

Earlier quoted context omitted.

Indeed. I have been buying IBM and then Lenovo Thinkpads for ages. I hate the thought that my next machine will be another brand. Lenovo: One customer lost. More to be lost.

Why stop buying Thinkpads? Lenovo have acknowledged the issue and are now trying to resolve it. Everybody makes mistakes but how they fix those problems tells you a lot about the culture of the company. Lenovo also made a terrible mistake in removing the physical click buttons, but is now reintroducing them across their entire laptop range for 2015. What I see is a company willing to listen and admit their mistakes.…

They have acknowledged that the issue exists, but not what it actually is.

Re: Lenovo Statement on Superfish

#135

Earlier quoted context omitted.

Indeed. I have been buying IBM and then Lenovo Thinkpads for ages. I hate the thought that my next machine will be another brand. Lenovo: One customer lost. More to be lost.

Why stop buying Thinkpads? Lenovo have acknowledged the issue and are now trying to resolve it. Everybody makes mistakes but how they fix those problems tells you a lot about the culture of the company. Lenovo also made a terrible mistake in removing the physical click buttons, but is now reintroducing them across their entire laptop range for 2015. What I see is a company willing to listen and admit their mistakes.…

I'd argue that so far, that's exactly the point, their response makes it worse.

"We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns" is a laughable statement to have issued.

I can understand the legal reasons for not admitting to the security issues. But outright saying that they can't find anything to suggest they exist indicates a company I wouldn't want to do business with.

To expand on that, in this case I know enough about the subject matter to understand that it's ridiculous to suggest there aren't security concerns. But I can't guarantee this will be the case for other problems. So going forward I'd probably avoid being a customer of a company who I have positive proof is prepared to issue blatantly incorrect statements about security issues.

Re: Lenovo Statement on Superfish

#136
post #27

> The relationship with Superfish is not financially significant; our goal was to enhance the experience for users. I would prefer for this to be a lie than for it to turn out for this statement to be true. Surely nobody at Lenovo honestly belived that ad injection improved user experience?

Well, a lot of people use their computer to purchase things. How do people know what to purchase? Ads! Therefore more ads = more knowledge about what to purchase and results in a better user experience QED /s.

You know, I often feel as though I'm living in a cave, because there are many things out in the world that I'm unaware of, and I often wonder if it's because I use Adblock.

Take Uber, for example. It's apparently a popular ride-sharing service, which I've only heard of recently due to a bunch of articles about them getting into trouble with the law. So how did that service get to be so popular to begin with? How did people first hear of them? I'm guessing that there were lots of banner ads for them all over the web, which I've never seen.

Of course, my curiosity as to what goods and services I might be missing out on is not strong enough to cause me to turn off Adblock, because good lord, the web user experience is horrible without it.

Re: Lenovo Statement on Superfish

#137
post #63
post #27

> The relationship with Superfish is not financially significant; our goal was to enhance the experience for users. I would prefer for this to be a lie than for it to turn out for this statement to be true. Surely nobody at Lenovo honestly belived that ad injection improved user experience?

> Surely nobody at Lenovo honestly belived that ad injection improved user experience? I can see the marketing folks honestly believing this. See, the problem with people in marketing is that they come up with ideas that sound good in theory but neglect to consider the implications. "Wouldn't it be great if I was presented with offers to buy things based on context clues in the web pages I'm browsing?" "Wouldn't it b…

Let's make broad claims about how people in tech marketing must be idiots!

See the funny thing is that I've worked in the PC making business and the parts business (Newegg) and the way this software makes it into the preload is not because of marketing, it's a product or finance decision. Hardware is a low margin business so you get paid to add in some pre-installed software and structure some revenue sharing deals. Lenovo isn't lying when it said that it wasn't financially meaningful; in fact, that's probably why they stopped installing it (not because they did some survey of users, etc.).

I don't think any reasonably competent marketer would ever suggest installing some adware as a "feature" so that they could market it. The fact that people are only finding out about this Superfish now meant that Lenovo and Lenovo marketing didn't advertise it's existence. Can someone show me some marketing material that say's "Lenovo PCs, now with more Superfish to enhance your online shopping experience."?

Re: Lenovo Statement on Superfish

#138
post #32
post #4

> We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns. I try to be measured around here, as hard as I can. I can't formulate a polite way to respond to this claim. Lenovo, you are full of shit, and maliciously so. There is no excuse, nor forgiveness, for what you've done here.

Can you ever imagine Apple pulling a stunt like this? No, because it’s astonishingly user hostile: Lenovo should be hanging their head in shame, not making out like it’s no big deal.

Apple told people for almost ten years (both on their website and in their retails stores) that "Macs cannot get viruses." They act like that wasn't a big deal.

Re: Lenovo Statement on Superfish

#139

Earlier quoted context omitted.

Indeed. I have been buying IBM and then Lenovo Thinkpads for ages. I hate the thought that my next machine will be another brand. Lenovo: One customer lost. More to be lost.

Why stop buying Thinkpads? Lenovo have acknowledged the issue and are now trying to resolve it. Everybody makes mistakes but how they fix those problems tells you a lot about the culture of the company. Lenovo also made a terrible mistake in removing the physical click buttons, but is now reintroducing them across their entire laptop range for 2015. What I see is a company willing to listen and admit their mistakes.…

This is not a mistake. This is an outright attack on the user, and it is straight-up disingenuous to claim it otherwise.

Anybody can MitM any HTTPS connection coming from these laptops. Anybody! The private key is public knowledge! This is so transcendentally bad and so impossible to implement without understanding the consequences that somebody should go to jail for this.

It is not a "mistake."

Re: Lenovo Statement on Superfish

#140
post #103

Earlier quoted context omitted.

And present any HTTPS cert of their choosing to any compromised visitors e.g https://b4nk0famer1ca.com/

Hm... I'm pretty sure that if you can actually MITM their connection (i.e. you can intercept and modify the packages, e.g. by setting up a rogue Wi-Fi hotspot), you can also fake the DNS and/or IP addresses, so you shouldn't have a problem compromising visitors of https://bankofamerica.com .

you don't need to fake IPs or DNS requests - if you have MITMed their connection then all their traffic flows through your machine and you can present whatever content you desire on any domain.
Post reply on HN