Live data from Hacker News

Lenovo Caught Installing Adware on New Computers

thenextweb.com

401–410 of 435 posts

Re: Lenovo Caught Installing Adware on New Computers

#401

Earlier quoted context omitted.

First thing I did when I saw that URL was to run it through Qualys' SSL Labs test. Multiple issues, no forward secrecy, weak ciphers, grade set to 'C'. Oh, the irony. https://www.ssllabs.com/ssltest/analyze.html?d=howsmyssl.com

Uh, because it needs to allow weak clients to connect in order to report on them?

Turns out you are right. Asked & answered on the project page today: https://github.com/jmhodges/howsmyssl/issues/44

Re: Lenovo Caught Installing Adware on New Computers

#402

Earlier quoted context omitted.

He didn't find the password in the clear, he found the private key in the clear. He brute-forced the password. I assume his reasoning for looking for the private key was similar to: this program creates a new certificate authority and installs it on this computer. In order to do this, it must have all necessary tools for doing so, including the private key it uses to create those certificates, in memory somewhere. Ev…

Read it again, he found the password in cleartext in the memory dump. From the blogpost: > I tried the small dictionary john.dict that comes with John-the-Ripper, and it didn't find anything. But of course, I don't need a real dictionary. The password is probably also in the clear in the memory dump. I could just use the file super.txt as my dictionary! I tried this, but it was taking a long time, with 150k unique li…

Yup, good catch.

Re: Lenovo Caught Installing Adware on New Computers

#403
post #89

Earlier quoted context omitted.

Asus is about it.

I thought so too, but my recent experience with a Zenbook has changed my view. WiFi drivers were so bad it took half a year after my purchase before the connection became stable (not dropping every 15 minutes requiring a reboot). Touchpad drivers were also a mess with awful kinetic scrolling. And just couple of weeks ago it stopped booting Windows altogehter (something related to ACPI I guess, Linux works if I don't…

Maybe Windows is terrible, I've heard lots of bad stuff about the wifi and touchpad drivers in particular. I installed xubuntu the day I got it and everything worked out of the box from day one. Power management on ubuntu 12.04 wasn't so great, but battery life became significantly better on 14.04.

Additionally, a roommate spilled a pint of beer on my computer and Asus replaced it for free, despite not having an accidental damage warranty.

Re: Lenovo Caught Installing Adware on New Computers

#404
post #267

Earlier quoted context omitted.

Not if the proxy checks the certificate of the site it's connecting to and doesn't trust it's own self-signed cert (there is no point in doing so if it's pure adware). But yeah... I have no idea what it does...

I honestly doubt that someone who was clueless and lazy enough to use the same self-signed certificate on all machines would put in the extra effort not to trust that certificate. Besides, the certificate is left behind after the software's uninstalled and no longer proxying connections.

Komodia, the company behind the tech contracted by the maker of SuperFish, actually (tries) to makes sure invalid and self-signed certificate do generates a warning in the browser. And then they password protect the private key with... the name of their company?!?

http://www.komodia.com/wiki/index.php?title=SSL_Digestor#Cer...

"Also the module tries to verify that the certificate is indeed signed by an approved signer, it will use the CA store of the browser used to verify that (for Internet Explorer the Windows store will be used, and for Firefox the NSS store will be used), if the certificate isn't legit, the created certificate will be created in a way it would raise an alert to protect the user."

A huge ugly hack...

Re: Lenovo Caught Installing Adware on New Computers

#405
post #222

Earlier quoted context omitted.

That appears to be the act of a nation-state though. I don't really sweat those, because I'm pretty sure if the NSA really wants in to my machine, I can't stop them.

They don't want in to just your machine though, they want a backdoor in to everyones machine, by default, without cause.

I'm not saying it is acceptable or that it doesn't matter. Just that, when it comes to my own personal computer, it isn't worth worrying about.

I have a lot of friends who haven't figured out the whole security-as-a-spectrum thing, and they spend a lot of time giving themselves grey hairs over adversaries that 1) they can't beat, 2) aren't worth beating, and 3) don't care about them anyway.

Re: Lenovo Caught Installing Adware on New Computers

#406
post #162
post #140

Earlier quoted context omitted.

The premium isn't as high as you think, particularly if you account for resale value. Didn't Priceonomics do a feature on this?

I'm not sure why anyone buys anything other than a home when accounting for resale value unless they're just trying to pull a pump-and-dump. For laptops, at least, I buy them and use them until they die. I've only owned three laptops in my life.

I'll usually buy a mac Apple refurb that's 9-12 months old (they're indistinguishable from new), then sell it a couple of years later. E.g. my 2010 MBA I bought for $900, then sold for $450 after two years. I'd rather do that than buy one new and use it for 6 years, which would cost about the same.

Re: Lenovo Caught Installing Adware on New Computers

#407

Earlier quoted context omitted.

I think worse than that, I see criminal charges being brought up for this including fraud, theft, etc.

Theft? Seriously?

They were making money (tens of millions) from software illegally installed, so definitely.

Re: Lenovo Caught Installing Adware on New Computers

#408
post #5

This is much worse than just installing adware. They install a web proxy which MITMs all web connections, including HTTPS by means of a pre-installed trusted root certificate. The root certificate is the same across all installs, and the private key is present on the machine (necessarily, to operate the proxy): https://twitter.com/fugueish/status/568258997578371072 Someone will extract the private key in the next few…

Imagine if the person you bought your house from told you "I've disabled all the locks on your doors and windows so that I can pop in from time to time and leave a fruit basket on your dining room table."

Re: Lenovo Caught Installing Adware on New Computers

#409

Earlier quoted context omitted.

Watch out, batter life is pretty crap! (About 2 hrs on my < 2yr old one)

The ones just released have a 15 hour battery (which even if it halves, is pretty good)

AnandTech says it's genuine: http://www.anandtech.com/show/8983/dell-xps-13-review/6.
Post reply on HN