Live data from Hacker News

Lenovo Statement on Superfish

news.lenovo.com

201–210 of 312 posts

Re: Lenovo Statement on Superfish

#201
post #169
post #110

Earlier quoted context omitted.

In contrast, I've been refusing to opt-in to my banks online statements for a long time now, simply because I want to have important stuff (e.g. my money) printed black-on-white. Email can be easily faked.

Would it not be easy to print a fake? I don't really understand why "can be easily faked" is how you're justifying this.

Some banks do have custom security envelopes with their company's name on the inside, although they'd also be easy to fake.

Re: Lenovo Statement on Superfish

#202
post #4

> We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns. I try to be measured around here, as hard as I can. I can't formulate a polite way to respond to this claim. Lenovo, you are full of shit, and maliciously so. There is no excuse, nor forgiveness, for what you've done here.

Indeed. I have been buying IBM and then Lenovo Thinkpads for ages. I hate the thought that my next machine will be another brand. Lenovo: One customer lost. More to be lost.

Or simply wipe the HDD and reinstall OS.

Re: Lenovo Statement on Superfish

#203
It's perplexing you still need to put a couple of days work into setting a up a computer. In the 90s it was all about getting all the peripherals to work. Now it's all about removing the bloatwear, data leaks, and security holes.

On a PC I do a Linux install and go through some extra settings.

On Android I install CyanogenMod with an IPtables firewall. The number of apps that try to raid your address book on Android is mind-boggling. When you set Privacy guard to "ask" instead of "deny" you will have so many popups that the phone is bogged down for a couple of minutes after startup.

Re: Lenovo Statement on Superfish

#204
post #42

Earlier quoted context omitted.

> We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns. I work at a large Telco/ISP and I understand how this kind of thing happens (though I'm not excusing it). First they come to the tech people and we explain exactly what's going on. Our managers translate it so they can understand it, and push it up with their name on it. Those Directors translate it so th…

It's also important to understand that in a case like this, upper management likely _wants_ the money from installing this on laptops (or their bosses do, or their boss's bosses do, and so on), so while they may act in good faith in translating the technical impacts of software like this to their management, they likely translate with a slight, unbeknownst to them bias.

It's pretty similar to what Comcast are doing by injecting ads into the web pages you visit.

Perhaps the real problem is that tech companies hire too many product/marketing managers, resulting in them having to cook up ridiculous money-making schemes in order to justify their own existence.

Re: Lenovo Statement on Superfish

#205

Earlier quoted context omitted.

Indeed. I have been buying IBM and then Lenovo Thinkpads for ages. I hate the thought that my next machine will be another brand. Lenovo: One customer lost. More to be lost.

I love my Lenovo X1 Carbon. It's a really nice machine. I do run linux so I know I'm not the average user, but they haven't lost my business despite this being an epic screw-up. I think they make good machines and I'll continue to buy from them in the future, but I'll be reformatting immediately just like I've always done with any PC I've ever bought from Dell, Gateway, Lenovo, etc, so I don't have to deal with the b…

What about the hardware level, which you cannot easily cleanup without knowing the full details of. If they're willing to try another route.

Re: Lenovo Statement on Superfish

#206

Earlier quoted context omitted.

If I'm reading you correctly, you're making the argument that Lenovo, the company that was just discovered to have been intentionally shipping a massive security vulnerability on their laptops, is still thought of by you as listening to their users better than Apple, the company that would never in their wildest dreams even remotely consider the idea of putting something like Superfish on their computers, simply beca…

Clearly Lenovo are stupid for bundling third-party ad-injection software, but who knows what Apple are doing behind closed doors? e.g. CarrierIQ in the baseband... etc.

Just to be clear, this is Apple, the company famous for putting user experience ahead of everything else (and often criticized by developers for putting user experience ahead of developer experience). Apple, the company that routinely tops customer satisfaction surveys. Apple, the company that has gone on the record time and time again about how user-focused they are.

There are plenty of valid things to criticize Apple for, but accusing them of sneaking malware onto their devices is not one of them.

Re: Lenovo Statement on Superfish

#207

> Users are not tracked nor re-targeted Have a look at code delivered by Superfish: https://www.superfish.com/ws/sf_preloader.jsp https://www.superfish.com/ws/sf_code.jsp And grep for track and retarget. Just two snippets: var url = sfDomain + "trackSession.action?userid=" + similarproducts.b.qsObj.userid + "&sessionid=-10&action=ud_host_failed"; and: function isRetargetingEnabled(){ if( similarproducts.b.enableRetar…

Not to be too snarky, but I don't think I'd trust somebody who wrote that function to have code where one could "not find any evidence to substantiate security concerns." Perhaps this is some sort of style thing specific to javascript, but wouldn't: function isRetargetingEnabled(){ return (similarproducts.b.enableRetargetingUnit && !isRetargetingBlackList()); } be the better way to write it? Sure say what you want ab…

I like your style better, but your function doesn't return 0 || 1 (yours returns true || false).

I also wouldn't read too much into it. It's unlikely that the same person wrote all the code involved, and many smart people I know write these kinds of functions, no matter how much I complain about it.

Re: Lenovo Statement on Superfish

#208

- Lenovo stopped preloading the software in January. My X1C was ordered on Feb 4th, and shipped Feb 9. I believe that my machine had this malware installed when I received it. On firefox, websites that would not normally have many ads, were filled with ads to the point where I couldn't use the sites. I am unable to prove my claims, as I formatted the HD and installed Linux to get rid of all the obvious bloat-ware. I…

[deleted]

Re: Lenovo Statement on Superfish

#209
post #144

Earlier quoted context omitted.

but what if you're a windows user? is the backup image on the drive adware free?

No, a windows user would have to buy a second copy of windows from microsoft and use that to install on the machine. Using Lenovo's recovery images will reinstall the same bloat that it originally came with

"No, a windows user would have to buy a second copy of windows from microsoft"

Or procure a legit, OEM install disk/image and reload using the key affixed to the bottom* of the laptop.

*Pre-8 days, now you get to "hope" the gUEFI recognizes the media and auto-populates the embedded key for you. When(not 'if' in my experience) it doesn't, then "buy more" is the only option outside of Linux.

Re: Lenovo Statement on Superfish

#210
post #27

> The relationship with Superfish is not financially significant; our goal was to enhance the experience for users. I would prefer for this to be a lie than for it to turn out for this statement to be true. Surely nobody at Lenovo honestly belived that ad injection improved user experience?

This would SEEM obvious because as techies we hate ads. But you can't extrapolate this to the general population. There was one time when I visited my mother. We started her instant messaging program, and we were presented with special offers. I recognized it as such within half a second, so I almost automatically checked the 'Do not show this again' checkbox. My mother alarmed me: "No, do not make it go away! I want…

If they make their money off of people legitimately interested, I wonder if there could be a way to convince the spammers that we're really not, so they can stop wasting their paper and bandwidth.
Post reply on HN