Live data from Hacker News

Lenovo Statement on Superfish

news.lenovo.com

141–150 of 312 posts

Re: Lenovo Statement on Superfish

#141
post #62
post #32

Earlier quoted context omitted.

Can you ever imagine Apple pulling a stunt like this? No, because it’s astonishingly user hostile: Lenovo should be hanging their head in shame, not making out like it’s no big deal.

No company is immune to making ridiculous statements - Apple told people not to hold the iPhone 4 the 'wrong way', for example[1]. I can believe that management at Lenovo simply can't understand how serious this incident is - they're unlikely to have the technical knowledge needed to understand how severe the security problem is. I'm sure there are hundreds of Lenovo engineers tearing their hair out in frustration ri…

Apple telling users not to hold the phone the wrong way is different in kind and several leagues of degree from "we are enabling anyone, ever, to MitM your connection to any website."

I believe you are raising this point in good faith, but it verges on disingenuous to compare them.

Re: Lenovo Statement on Superfish

#142
post #88

Earlier quoted context omitted.

I am mindblown too. I thought that it was pretty obvious by now to everyone that ads do not show you the offer that is best for you; they show you the offer that's best for the company, which means you spending more money on something subpar. I find ads anything but useful.

So how exactly do you expect people to find out about your product if you don't advertise it? Even word of mouth requires a first sale, which generally requires... advertising.

There's advertising, and then there's advertising. Maybe a hundred years ago ads were about product discovery, they are not about that anymore. For most of the needs we have there are already products so you can just discover the product categories via well... interaction with other people. A new class of product gets often gets its spread organically, or at least via product-discovery-ads.

So for example, you didn't learn about the existence of cameras via ads - you probably saw your parents or friends shooting photos when you were a child. And you know that the ads of cameras you see on the web are offering subpar products, and you're better off searching for a camera that fulfills your needs yourself.

Another example, of a relatively new category - iBeacons. You probably read about them on the Internet, or maybe in a magazine like The Economist. Sure, maybe you read an infomercial, but what you've learend is that there is this new category of products, and that they can help you make phones more context-aware. But if you're thinking about what beacons to buy, you are again better off researching yourself and consciously ignoring anything that looks like an ad.

Re: Lenovo Statement on Superfish

#143
post #123

While this kind of foistware sucks, I'm also a bit dismayed by the seeming domain-specificity of peoples' privacy concerns. Do a simple tracker on a desktop, and people freak out. But all you have to do is change the form factor and UI metaphor to mobile and people are absolutely fine with constant location tracking, ambient sound being uploaded to the cloud (SIRI, etc.), a camera and a microphone that can be activat…

I would agree with you if this were only about adware. The problem is that the adware opens a massive security hole that is exploitable by everybody.

The Lenovo adware wants to hijack SSL connections. To do so, it installs its own CA, and the private key for that CA can be (and has been) extracted. This means that if you own such a laptop and access your bank's SSL website from a random coffee shop, anybody could MitM you, since they can use the publically available "private" key of the rogue CA to impersonate your bank.

Smart phones enable turn-key surveillance-based dictatorships beyond anything we've ever seen in the west, but unlike this Lenovo thing, it is not an immediate threat. Hence people react differently to it.

Re: Lenovo Statement on Superfish

#144
post #129

Earlier quoted context omitted.

Indeed. I have been buying IBM and then Lenovo Thinkpads for ages. I hate the thought that my next machine will be another brand. Lenovo: One customer lost. More to be lost.

If you re-installed your OS and didn't use the factory image (which always includes other bloatware), then you were not affected. Or if you installed another OS (Linux, BSD, etc) then you were not affected. I love my thinkpad... but I've always paved over the factory image the moment I got my new laptop. This is egregious beyond a doubt, but it does not affect me so I'm not worried about buying more of their laptops.

but what if you're a windows user? is the backup image on the drive adware free?

Re: Lenovo Statement on Superfish

#145
post #85
post #32

Earlier quoted context omitted.

Can you ever imagine Apple pulling a stunt like this? No, because it’s astonishingly user hostile: Lenovo should be hanging their head in shame, not making out like it’s no big deal.

You mean like with spotlight in Yosemite?

I'm on record around here about being angry with Yosemite sending requests off-machine, and it's the first thing I turn off. Lenovo enables anyone, anywhere, to MitM your bank.

Difference in kind. Massive, massive difference in kind.

Re: Lenovo Statement on Superfish

#146
post #42
post #4

> We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns. I try to be measured around here, as hard as I can. I can't formulate a polite way to respond to this claim. Lenovo, you are full of shit, and maliciously so. There is no excuse, nor forgiveness, for what you've done here.

> We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns. I work at a large Telco/ISP and I understand how this kind of thing happens (though I'm not excusing it). First they come to the tech people and we explain exactly what's going on. Our managers translate it so they can understand it, and push it up with their name on it. Those Directors translate it so th…

It's also important to understand that in a case like this, upper management likely _wants_ the money from installing this on laptops (or their bosses do, or their boss's bosses do, and so on), so while they may act in good faith in translating the technical impacts of software like this to their management, they likely translate with a slight, unbeknownst to them bias.

Re: Lenovo Statement on Superfish

#147
Repeating this from the other thread: people should file complaints with their state consumer protection division. There are probably at least one or two attorneys general in the country who would love to make an example out of Lenovo ("big bad foreign company", etc.).

Here's the complaint form for Massachusetts: http://www.eform.ago.state.ma.us/ago_eforms/forms/piac_ecomp...

Some state AGs are active on Twitter too, which might get more direct visibility.

Re: Lenovo Statement on Superfish

#148
post #4

> We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns. I try to be measured around here, as hard as I can. I can't formulate a polite way to respond to this claim. Lenovo, you are full of shit, and maliciously so. There is no excuse, nor forgiveness, for what you've done here.

Indeed. I have been buying IBM and then Lenovo Thinkpads for ages. I hate the thought that my next machine will be another brand. Lenovo: One customer lost. More to be lost.

It was only installed on consumer laptops so you probably wouldn't have it anyway....

Re: Lenovo Statement on Superfish

#149
post #123

While this kind of foistware sucks, I'm also a bit dismayed by the seeming domain-specificity of peoples' privacy concerns. Do a simple tracker on a desktop, and people freak out. But all you have to do is change the form factor and UI metaphor to mobile and people are absolutely fine with constant location tracking, ambient sound being uploaded to the cloud (SIRI, etc.), a camera and a microphone that can be activat…

A desktop/laptop is a computer. A smartphone is a computer. Why the different reaction?

They're still two different classes. Smartphones (at least the mainstream Android, iOS and Windows platforms) aren't even self-hosting yet, so they're definitely in their infancy and unlikely to displace the microcomputers we have until said shift occurs, regardless of widespread commentary to the contrary.

By the way, "trusted computing" was backed by a ton of other companies besides Microsoft (I don't even think Microsoft were remotely the first), and it is most certainly not dead in the slightest.

Re: Lenovo Statement on Superfish

#150
post #123

While this kind of foistware sucks, I'm also a bit dismayed by the seeming domain-specificity of peoples' privacy concerns. Do a simple tracker on a desktop, and people freak out. But all you have to do is change the form factor and UI metaphor to mobile and people are absolutely fine with constant location tracking, ambient sound being uploaded to the cloud (SIRI, etc.), a camera and a microphone that can be activat…

A big part of this is convenience, I guess. People were flipping out about Microsoft's trusted computing because it was seen as a big company locking things down. Apple and Android managed to wrap it in a cool UX (and arguably good value proposition of curated content - which is still not as good as one would like given how much crap you can find on the app store) - and general population started using it before techies got around to shouting. It's too late now.

Another, maybe smaller part, is trust. I for one sign into Chrome with my Google ID and enable all location services, etc. on my Android phone because I still trust Google and the Don't Be Evil mantra. I haven't been convinced yet that they're a bad actor (OTOH I can't say that about Apple). I admit it's probably very subjective.

Post reply on HN