Live data from Hacker News

Lenovo Statement on Superfish

news.lenovo.com

151–160 of 312 posts

Re: Lenovo Statement on Superfish

#151

Earlier quoted context omitted.

Indeed. I have been buying IBM and then Lenovo Thinkpads for ages. I hate the thought that my next machine will be another brand. Lenovo: One customer lost. More to be lost.

Why stop buying Thinkpads? Lenovo have acknowledged the issue and are now trying to resolve it. Everybody makes mistakes but how they fix those problems tells you a lot about the culture of the company. Lenovo also made a terrible mistake in removing the physical click buttons, but is now reintroducing them across their entire laptop range for 2015. What I see is a company willing to listen and admit their mistakes.…

[deleted]

Re: Lenovo Statement on Superfish

#152

They disabled it server-side? What about the CA certificate in all these Lenovo users' trust stores that blackhats can now use to MITM with wild abandon?

It enhances the users experience when being MITM'd.

But yeah, the removal instructions mention that the certificate won't be removed, which is quite dangerous.

EDIT: And users removing the cert would be unable to load https pages, which is a tricky situation.

Re: Lenovo Statement on Superfish

#153

Earlier quoted context omitted.

Yeah and businesses run their own Windows images. Whatever software is preloaded doesn't matter.

Unless their Windows image is based on the out-of-the-box OEM install.

I would imagine that any company imaging their hardware has their own custom image to coincide with their windows licensing agreement and not on whatever was on the first box.

Re: Lenovo Statement on Superfish

#154
post #63
post #27

> The relationship with Superfish is not financially significant; our goal was to enhance the experience for users. I would prefer for this to be a lie than for it to turn out for this statement to be true. Surely nobody at Lenovo honestly belived that ad injection improved user experience?

> Surely nobody at Lenovo honestly belived that ad injection improved user experience? I can see the marketing folks honestly believing this. See, the problem with people in marketing is that they come up with ideas that sound good in theory but neglect to consider the implications. "Wouldn't it be great if I was presented with offers to buy things based on context clues in the web pages I'm browsing?" "Wouldn't it b…

"Wouldn't it be great if I was presented with offers to buy things based on context clues in the web pages I'm browsing?"

Sounds a lot like Google ;-)

Re: Lenovo Statement on Superfish

#155
post #123

While this kind of foistware sucks, I'm also a bit dismayed by the seeming domain-specificity of peoples' privacy concerns. Do a simple tracker on a desktop, and people freak out. But all you have to do is change the form factor and UI metaphor to mobile and people are absolutely fine with constant location tracking, ambient sound being uploaded to the cloud (SIRI, etc.), a camera and a microphone that can be activat…

> ambient sound being uploaded to the cloud (SIRI, etc.)

To the best of my understanding, Siri doesn't do this. Siri listens, locally and on-device, for the hot phrase. (I know that the Moto X does that for 'Okay, Google Now'.)

Anyway, to the other points: I get something for providing information to Google. My location isn't terribly important to me and the benefits outweigh the risk. Ditto an online internet connection. My phones, iPhone and Android alike, both run whatever software I want--Cydia was the first thing I installed on my iPhone and Android accepts applications without qualm. (And I don't use applications that can turn the camera or microphone on without my knowledge.)

This is spying on my e-mail and my bank. It has literally no positive attributes. There's just such a massive difference to me that I get confused at your core claim.

Re: Lenovo Statement on Superfish

#156
post #123

While this kind of foistware sucks, I'm also a bit dismayed by the seeming domain-specificity of peoples' privacy concerns. Do a simple tracker on a desktop, and people freak out. But all you have to do is change the form factor and UI metaphor to mobile and people are absolutely fine with constant location tracking, ambient sound being uploaded to the cloud (SIRI, etc.), a camera and a microphone that can be activat…

This is not about surveillance or privacy.

This is a massive, well-established company deliberately introducing a gigantic security hole into all secure internet services, including the ones you use for online payments, banking, and governmental services. It's a security hole that can be exploited by anyone with moderate technical knowledge, and it was all done for the sake of showing you ads.

Re: Lenovo Statement on Superfish

#157
post #54
post #35

Earlier quoted context omitted.

Why does lenovo thinkpad have to be the only line of laptops that has a trackpoint by default? How hard can it be to include it for other brands? This is a very important feature for some people and it limits their choice to thinkpads and (AFAIK) some HP laptops.

I've had track points on hp and dell laptops (I always disable them)

Also some Toshiba laptops....

Re: Lenovo Statement on Superfish

#158

> Users are not tracked nor re-targeted Have a look at code delivered by Superfish: https://www.superfish.com/ws/sf_preloader.jsp https://www.superfish.com/ws/sf_code.jsp And grep for track and retarget. Just two snippets: var url = sfDomain + "trackSession.action?userid=" + similarproducts.b.qsObj.userid + "&sessionid=-10&action=ud_host_failed"; and: function isRetargetingEnabled(){ if( similarproducts.b.enableRetar…

Outstanding. It's like a ridiculous Law & Order episode where the defendant goes "I wasn't even in town that night."

"So what's your face doing on all of these security cameras at the scene of the crime?"

"... uh..."

Re: Lenovo Statement on Superfish

#160
post #83
post #51

Microsoft seems to have a vice like grip over OEM's regarding preloading windows on every product they sell without exception, IMHO this is a terrible thing, but can't they do at least a little good and prevent OEM's from shipping anything other than a pristine image with no preloaded software? Surely the endless bundled crapware from every OEM just gives Windows a bad reputation in the long term. The popularity of c…

They tried dictating what vendors could pre-load, and were taken to court by the US Justice Dept, along with a large number of states AGs.

Correct. So OEMs can load whatever crapware they like, and Microsoft doesn't even know what they're loading. The idea of a "vice like grip" is nonsense.

What Microsoft does instead is offer Signature editions that are crapware free....

Post reply on HN