Live data from Hacker News

Lenovo Statement on Superfish

news.lenovo.com

181–190 of 312 posts

Re: Lenovo Statement on Superfish

#181

Earlier quoted context omitted.

Indeed. I have been buying IBM and then Lenovo Thinkpads for ages. I hate the thought that my next machine will be another brand. Lenovo: One customer lost. More to be lost.

Why stop buying Thinkpads? Lenovo have acknowledged the issue and are now trying to resolve it. Everybody makes mistakes but how they fix those problems tells you a lot about the culture of the company. Lenovo also made a terrible mistake in removing the physical click buttons, but is now reintroducing them across their entire laptop range for 2015. What I see is a company willing to listen and admit their mistakes.…

> Why stop buying Thinkpads?

Panasonic makes much higher quality hardware than Lenovo (and Apple for that matter). Panasonic also doesn't preload bloatware onto Windows.

http://www.panasonic.com/business/toughbook/semi-rugged-lapt...

Re: Lenovo Statement on Superfish

#182
- Lenovo stopped preloading the software in January.

My X1C was ordered on Feb 4th, and shipped Feb 9.

I believe that my machine had this malware installed when I received it. On firefox, websites that would not normally have many ads, were filled with ads to the point where I couldn't use the sites.

I am unable to prove my claims, as I formatted the HD and installed Linux to get rid of all the obvious bloat-ware.

I really enjoy the laptop. But if I was less tech savvy and unable to format/installLinux I would probably have returned the machine (the ads were really really intrusive)

Re: Lenovo Statement on Superfish

#183
post #122

Earlier quoted context omitted.

This would SEEM obvious because as techies we hate ads. But you can't extrapolate this to the general population. There was one time when I visited my mother. We started her instant messaging program, and we were presented with special offers. I recognized it as such within half a second, so I almost automatically checked the 'Do not show this again' checkbox. My mother alarmed me: "No, do not make it go away! I want…

The flip side is that there are genuine discounts for many products that save you money with no strings attached. It's just differential pricing: they want to sell their products for more money to people who want to spend more money. Or it's part of an affiliate advertising program and the way to ensure affiliate codes get entered by buyers is to offer them a discount. I hate many ads too but I'll seek out discounts…

Grocery shops have another trick up their sleeve - they lower prices on some products, but raise prices of complementary goods. So you can have a genuine discount on bread, and at the same time heavily overpriced cheese. They're betting on you not caring enough to split your shopping between multiple venues.

My mother recently told me how she's tired of keeping track of prices (or price/quality tradeoff) in 5+ different shops - she can save a lot of money and buy good quality products at the same time as long as she knows what to buy where. But she's doing bulk shopping. I probably wouldn't bother walking around the hood to get one item cheaper.

Re: Lenovo Statement on Superfish

#184
I have a Lenovo laptop and had the superfish root cert installed. I also have a "Nuance" trusted root certificate installed. It's a SHA1RSA certificate issued by Nuance, expiring in January 2040 (serial 9e ef 9d f5 9a...), thumbprint (51 2d 19 4d 28 64...). It says it's usable for everything. Does anyone know about this one?

Re: Lenovo Statement on Superfish

#185

Earlier quoted context omitted.

Keyword there is "snail mail." You're saying you really want this stuff in your mailbox every week? I don't want any snail mail(of any kind), any week but it's something I still have to live with.

Yes, is it really that hard to take 5 seconds out of your day and check snail mail? I get that people don't like it, but let's be real, it's not that big of an inconvenience.

Well, if this is opt-in mail, it's all cool. Where I live I, along with all my neighbours, have something like half a kilogram of spam mail weekly, all of it (except maybe first flyer from a newly-opened pizza place) goes straight to thrash. Scale this up to 1-million city or 30-million country and think of all this wasted paper, paint, electricity, fuel and labour.

Re: Lenovo Statement on Superfish

#186
post #12

Earlier quoted context omitted.

Sadly no. Businesses will still buy Thinkpads like candies.

Yeah and businesses run their own Windows images. Whatever software is preloaded doesn't matter.

Big companies, yes. Small businesses, not so much.

There's certainly an unrealized support cost. But in my experience, it's pretty common to see several different manufacturers and OSs across a small business. When they need a new laptop, they're either picking up what's cheap at Best Buy or handing down machines when the boss gets a new one.

Re: Lenovo Statement on Superfish

#187
>To be clear, Superfish technology is purely based on contextual/image and not behavioral. It does not profile nor monitor user behavior. It does not record user information. It does not know who the user is. Users are not tracked nor re-targeted. Every session is independent.

We've heard this song and dance before. Excuse my skepticism, but I don't believe you and until we can see some source code, I won't believe you.

Re: Lenovo Statement on Superfish

#188
post #95

Earlier quoted context omitted.

Not even a hint of an admission on the certificate issue, I'm not surprised. If they admit they knew about the root certificate or even acknowledge its existence after the discovery, they could open themselves up to legal liability if someone's bank account or identity is compromised. This really sucks because I used to recommend Lenovo workstations and ThinkPad laptops to people; it really is good hardware at a dece…

They actually reference the root certificate in their removal instructions: "Uninstalling Superfish Visual Discovery Go to Control Panel > Uninstall a Program Select Visual Discovery > Uninstall Superfish will be removed from Program Files and Program Data directories, files in user directory will stay intact for the privacy reason. Registry entry and root certificate will remain as well. The Superfish service will s…

"This article will be updated with additional instructions on clean up of deactivated files and removal of certificate shortly."

This was just edited, here is the post before that: https://web.archive.org/web/20150219151726/http://forums.len...

Re: Lenovo Statement on Superfish

#189

> Users are not tracked nor re-targeted Have a look at code delivered by Superfish: https://www.superfish.com/ws/sf_preloader.jsp https://www.superfish.com/ws/sf_code.jsp And grep for track and retarget. Just two snippets: var url = sfDomain + "trackSession.action?userid=" + similarproducts.b.qsObj.userid + "&sessionid=-10&action=ud_host_failed"; and: function isRetargetingEnabled(){ if( similarproducts.b.enableRetar…

Not to be too snarky, but I don't think I'd trust somebody who wrote that function to have code where one could "not find any evidence to substantiate security concerns."

Perhaps this is some sort of style thing specific to javascript, but wouldn't:

    function isRetargetingEnabled(){
        return (similarproducts.b.enableRetargetingUnit &&
                !isRetargetingBlackList());
    }
be the better way to write it? Sure say what you want about micro-optimizations, but the function appears to be used in a boolean context, so shouldn't it just return the if condition? Things like this are why I have trouble trusting security claims.

EDIT: Fixed double-negative

Re: Lenovo Statement on Superfish

#190
There's a scene in the movie The Rum Diary where Sanderson says roughly that the way to sell the public on the idea of building a hotel on an untouched island is to start by trying to build 20 hotels. Public outrage will occur, people will write their politicians, and finally a compromise will be reached, in which you get to build only one hotel. But the trick is, that's what you wanted to do in the first place. In the end, this compromise wasn't good enough: the result is still horrible.

This is roughly what Lenovo is trying to pull off here.

> Superfish was previously included on some consumer notebook products shipped in a short window between September and December to help customers potentially discover interesting products while shopping.

This is the compromise being offered. They're claiming, "We didn't violate your privacy, we didn't violate your security, we just wanted to help you discover interesting products."

Superfish opens up all sorts of security holes and privacy concerns, but it's probably true that this wasn't Lenovo's intention (not yet, anyway). But to accept this as a compromise would be to give Lenovo the thing they want in the first place: to serve ads into our web searches. And that in itself is deplorable. It is not acceptable for companies to force their agendas on us.

Lenovo's only defense here is that they were doing something disgusting. We should not accept this compromise.

Post reply on HN