Live data from Hacker News

Lenovo Statement on Superfish

news.lenovo.com

211–220 of 312 posts

Re: Lenovo Statement on Superfish

#211
The absolute best part?

"Superfish will be removed from Program Files and Program Data directories, files in user directory will stay intact for the privacy reason. Registry entry and root certificate will remain as well. The Superfish service will stop working as soon as it is uninstalled via above process, and following reboot."

Per Lenovo's removal instructions [1], the compromised root certificate will still be installed and trusted. This is completely laughable.

[1] http://forums.lenovo.com/t5/Lenovo-P-Y-and-Z-series/Removal-...

Re: Lenovo Statement on Superfish

#214
> We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns.

Apparently a wildcard SSL certificate valid for every domain on the internet installed in a certificate store isn't a security concern.

Apparently said SSL certificate having a extractable private key installed within a user certificate store isn't a security concern

And apparently leaving said certificate behind in the certificate store even after uninstalling the crapware (according to a very reliable InfoSec Taylor Swift) isn't a security concern.

Wow? Wow.

Re: Lenovo Statement on Superfish

#215
post #4

> We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns. I try to be measured around here, as hard as I can. I can't formulate a polite way to respond to this claim. Lenovo, you are full of shit, and maliciously so. There is no excuse, nor forgiveness, for what you've done here.

Speaking of Lenovo being full of shit, there's also this gem: > The relationship with Superfish is not financially significant; our goal was to enhance the experience for users. Right. You loaded adware onto users' computers, not for financial gain, but to enhance the experience for them.

I totally detest such language.

Re: Lenovo Statement on Superfish

#216

Earlier quoted context omitted.

Indeed. I have been buying IBM and then Lenovo Thinkpads for ages. I hate the thought that my next machine will be another brand. Lenovo: One customer lost. More to be lost.

Why stop buying Thinkpads? Lenovo have acknowledged the issue and are now trying to resolve it. Everybody makes mistakes but how they fix those problems tells you a lot about the culture of the company. Lenovo also made a terrible mistake in removing the physical click buttons, but is now reintroducing them across their entire laptop range for 2015. What I see is a company willing to listen and admit their mistakes.…

>What I see is a company willing to listen and admit their mistakes.

Apply this to a human who did something similar.

"I'm sorry I purposefully allowed my previous employer's systems to be infected by a virus in return for payment. I'm willing to admit it was a mistake and I've taken steps to correct it."

Would you honestly hire someone like that to be a sysadmin?

Re: Lenovo Statement on Superfish

#217
post #169
post #110

Earlier quoted context omitted.

In contrast, I've been refusing to opt-in to my banks online statements for a long time now, simply because I want to have important stuff (e.g. my money) printed black-on-white. Email can be easily faked.

Would it not be easy to print a fake? I don't really understand why "can be easily faked" is how you're justifying this.

It is less likely that someone would send a falsified bank document through the mail, as mail fraud is a federal crime with harsher sentences than most online versions of spam/phishing.

Also records are kept for mail regarding where it was received by the post office (which likely has security cameras), when, who is on the return address and the recipient. There is physical evidence of who has touched a piece of mail such as fingerprints, hair, DNA etc.

This is part of why you don't get 50 letters from nigerian princes each day

Re: Lenovo Statement on Superfish

#218
post #179

Earlier quoted context omitted.

It depends on what you're doing of course. Normal usage (playing music/Youtube, browsing firefox, coding, opening up some PDFs) gives me about 6-8 hours I'd say, I get about 3 hours of (modded) minecraft, which is quite the battery drain. this is on Gentoo (Awesome as WM) so the background drain is pretty low. It's good enough that I never really pay attention to it. upower says the battery is designed to store up to…

Is the battery controller programmable from Linux? E.g. can you set charging thresholds? Is there any hardware in it that doesn't work in Linux?

I don't know about the battery controller, all of it works with Linux (System76 is a Linux retailer after all).

Re: Lenovo Statement on Superfish

#219

Earlier quoted context omitted.

Why stop buying Thinkpads? Lenovo have acknowledged the issue and are now trying to resolve it. Everybody makes mistakes but how they fix those problems tells you a lot about the culture of the company. Lenovo also made a terrible mistake in removing the physical click buttons, but is now reintroducing them across their entire laptop range for 2015. What I see is a company willing to listen and admit their mistakes.…

> Why stop buying Thinkpads? Panasonic makes much higher quality hardware than Lenovo (and Apple for that matter). Panasonic also doesn't preload bloatware onto Windows. http://www.panasonic.com/business/toughbook/semi-rugged-lapt...

No trackpoint.

Re: Lenovo Statement on Superfish

#220
post #32

Earlier quoted context omitted.

Can you ever imagine Apple pulling a stunt like this? No, because it’s astonishingly user hostile: Lenovo should be hanging their head in shame, not making out like it’s no big deal.

The big difference is you don't mind when Apple does things like this. If you have "Hey, Siri" enabled then your phone's microphone is on all the time listening to everything you say. But I don't see a lot of people crying foul over that.

The big difference is that "Hey, Siri" isn't a privacy threat at all, and that Apple doesn't generally allow people to snoop on all of my supposedly-secure traffic and then say "oh, there was no problem" when confronted with it.

About the closest they've come to that was the "goto fail" bug from a year ago or so, and that gave every appearance of being a mistake, and Apple didn't try to claim that it wasn't a problem (although they were, as usual, pretty quiet about the exact nature of the problem).

Post reply on HN