Live data from Hacker News

Lenovo Statement on Superfish

news.lenovo.com

221–230 of 312 posts

Re: Lenovo Statement on Superfish

#221
post #144

Earlier quoted context omitted.

but what if you're a windows user? is the backup image on the drive adware free?

No, a windows user would have to buy a second copy of windows from microsoft and use that to install on the machine. Using Lenovo's recovery images will reinstall the same bloat that it originally came with

It's actually much easier than that - no secondary purchase is required with Windows 8

https://www.thurrott.com/uncategorized/1146/clean-pc-walkthr...

Re: Lenovo Statement on Superfish

#222
"We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns."

http://forums.lenovo.com/t5/Lenovo-P-Y-and-Z-series/Removal-...

"This article will be updated with additional instructions on clean up of deactivated files and removal of certificate shortly."

This was just edited in, here is the post before that: https://web.archive.org/web/20150219151726/http://forums.len...

So, Lenovo, why should we remove this certificate after all? Any security concerns perhaps?

Re: Lenovo Statement on Superfish

#223
post #175

Earlier quoted context omitted.

I love my Lenovo X1 Carbon. It's a really nice machine. I do run linux so I know I'm not the average user, but they haven't lost my business despite this being an epic screw-up. I think they make good machines and I'll continue to buy from them in the future, but I'll be reformatting immediately just like I've always done with any PC I've ever bought from Dell, Gateway, Lenovo, etc, so I don't have to deal with the b…

If they are willing to compromise you on a software level, what makes you think they aren't prepared to do so on the hardware level (presuming they already aren't).

At some point you're going to have to trust the vendor and the supply chain... unless you're prepared to build your own computer by soldering home-made components onto a bread-board! ;-)

Re: Lenovo Statement on Superfish

#224

Earlier quoted context omitted.

Indeed. I have been buying IBM and then Lenovo Thinkpads for ages. I hate the thought that my next machine will be another brand. Lenovo: One customer lost. More to be lost.

> Lenovo: One customer lost. More to be lost. Never purchased a Lenovo but I was bent on using one for my next machine. No longer. Their lies about it "not being a risk" have put the affected customers at immense risk.

Doesn't matter what machine you're using if your ISP e.g. Comcast is injecting ads into the web pages you visit!

Re: Lenovo Statement on Superfish

#225
post #4

> We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns. I try to be measured around here, as hard as I can. I can't formulate a polite way to respond to this claim. Lenovo, you are full of shit, and maliciously so. There is no excuse, nor forgiveness, for what you've done here.

Is there a proof of concept that exploits this ?

Close:

http://blog.erratasec.com/2015/02/extracting-superfish-certi...

Re: Lenovo Statement on Superfish

#226

Earlier quoted context omitted.

If I'm reading you correctly, you're making the argument that Lenovo, the company that was just discovered to have been intentionally shipping a massive security vulnerability on their laptops, is still thought of by you as listening to their users better than Apple, the company that would never in their wildest dreams even remotely consider the idea of putting something like Superfish on their computers, simply beca…

Clearly Lenovo are stupid for bundling third-party ad-injection software, but who knows what Apple are doing behind closed doors? e.g. CarrierIQ in the baseband... etc.

Who knows what is doing behind closed doors? What am I doing behind closed doors? What are you doing behind closed doors?

While there is a chance someone may be doing something bad behind closed doors, that cannot be used as a reason for why they are worse than someone whose door we have opened and found doing something bad.

Re: Lenovo Statement on Superfish

#227

Earlier quoted context omitted.

Apple told people for almost ten years (both on their website and in their retails stores) that "Macs cannot get viruses." They act like that wasn't a big deal.

The number one source of viruses on a Mac is anti-virus software, don't install it. No system is impervious, there are levels of risk. Apparently the highest possible risk is running a stock Lenovo.

I don't run AV software on my Mac because the threat and possible consequences are sufficiently limited.

But I've never heard about AV software itself being a vector. Where can I find out more?

Re: Lenovo Statement on Superfish

#228

Earlier quoted context omitted.

Their response is basically that this wasn't even a problem, but they'll still stop because people are making a big deal out of it for no reason and it's good to keep people happy, even when they're idiots. This seems like a pretty good reason to drop them. When you catch somebody misbehaving, and their response is "fine, I'll stop, but it wasn't a problem" then you can't trust them at all.

> When you catch somebody misbehaving, and their response is "fine, I'll stop, but it wasn't a problem" then you can't trust them at all. Indeed. This kind of response is one of the most disrespectful things you can do to another person. "Hey, what are so upset about? Chill, it wasn't a big deal anyway!"

I'm kind of impressed that their PR guys are so incompetent. Their statement is so nakedly condescending, they might as well have straight-up said, "You guys are full of shit, but we'll stop just so you'll shut up about it."

Re: Lenovo Statement on Superfish

#229
post #12
post #8

Lenovo is going to lose more through how they handle this than through the fact that they did it in the first place.

Sadly no. Businesses will still buy Thinkpads like candies.

As a subcontractor for BIA and DOI, I can sure you that news has gone around and we will add all Lenovo products to the list of items no to purchase.

Re: Lenovo Statement on Superfish

#230
post #209

Earlier quoted context omitted.

No, a windows user would have to buy a second copy of windows from microsoft and use that to install on the machine. Using Lenovo's recovery images will reinstall the same bloat that it originally came with

"No, a windows user would have to buy a second copy of windows from microsoft" Or procure a legit, OEM install disk/image and reload using the key affixed to the bottom* of the laptop. *Pre-8 days, now you get to "hope" the gUEFI recognizes the media and auto-populates the embedded key for you. When(not 'if' in my experience) it doesn't, then "buy more" is the only option outside of Linux.

This is totally correct - I just meant that using Lenovos provided installation media would not resolve the issue.

You can definitely use an OEM disk of your exact version with your printed serial. I too have had to procure new keys for win8 machines (did two last week that wouldn't recognize the keys on my machine)

Post reply on HN