Live data from Hacker News

Lenovo Statement on Superfish

news.lenovo.com

271–280 of 312 posts

Re: Lenovo Statement on Superfish

#271
post #32
post #4

> We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns. I try to be measured around here, as hard as I can. I can't formulate a polite way to respond to this claim. Lenovo, you are full of shit, and maliciously so. There is no excuse, nor forgiveness, for what you've done here.

Can you ever imagine Apple pulling a stunt like this? No, because it’s astonishingly user hostile: Lenovo should be hanging their head in shame, not making out like it’s no big deal.

Plus, they have no reason to do so, because unlike Lenovo, they make a healthy profit on their hardware. (I believe IBM was in the same position with its ThinkPads back in the day.) In contrast, the bargain PC laptop makers have little or no profit margin on the hardware itself, so they're always looking for other ways to eke out a bit more money.

This is why I'm willing to pay a bit more for things I rely upon and care about. If you were a climber, would you try to save a buck by using an off-brand, bargain rope?

Re: Lenovo Statement on Superfish

#272
post #103

Earlier quoted context omitted.

And present any HTTPS cert of their choosing to any compromised visitors e.g https://b4nk0famer1ca.com/

Hm... I'm pretty sure that if you can actually MITM their connection (i.e. you can intercept and modify the packages, e.g. by setting up a rogue Wi-Fi hotspot), you can also fake the DNS and/or IP addresses, so you shouldn't have a problem compromising visitors of https://bankofamerica.com .

The point being that you don't have to MITM their connection. The private key is in the wild, you can sign a cert and host it anywhere on the internet. Any visitors who have that see that cert signed by that root cert will say "yep, fine, go ahead".

So then you spam the world with "Important message from Lenovo" and hope they click on https://len0v0.com and install your important update

Re: Lenovo Statement on Superfish

#273
post #45

Earlier quoted context omitted.

> Can you ever imagine Apple pulling a stunt like this? No Why would you jump to that conclusion? Apple is just a company... and through the right view-port, even something like this can appear to be "consumer oriented" to management ("we're helping customers locate products and services easier"). Recently Canonical thought it was a great idea to bake-in Amazon ads into their search lens... so ads and product placeme…

Apple is definitely not immune to stupid things. They've done a lot of stupid things. Apple have also made tons of mistakes when it comes to security and privacy. But I still have a hard time seeing Apple ever intentionally adding a feature that proxies all a user's encrypted connections to inspect the content and insert ads. Tim Cook's recent speech at the Cybersecurity summit sounded pretty earnest to me https://ww…

Given that Apple has made a priority of elevating convenience above security, I'm not sure how seriously to take Cook on the subject of the importance of privacy and security.

Re: Lenovo Statement on Superfish

#274
post #15
post #13

I was considering getting a Lenovo X1 Carbon to run linux on. I'd be installing a clean image, so no Superfish, but I still don't want to give money to Lenovo right now. What alternative linux laptops are there? (aside from macs)

Dell sells laptops with Ubuntu, its $100 cheaper. Most awesome is probably XPS 13" 2015, but it does not have official support yet.

Is there a version that's not touchscreen?

Re: Lenovo Statement on Superfish

#275
post #264
post #255

Earlier quoted context omitted.

Same here. I just ordered a Lenovo desktop 3 days ago for a family member. Seriously thinking about canceling the order now even though that machine should not be affected. I've been recommending Lenovo to lots of people, and I personally have a ThinkPad and a Yoga 2 Pro. I found the Superfish certificate on the Yoga this morning. This glib and dismissive statement is just adding insult to injury. As ambivalent as I…

I just can't let this statement pass. You don't support lawsuits (all those pricks abusing the courts, extorting money from companies!)... right up until the hot second a company screws you , and then the courts are an appropriate recourse. Maybe you could consider becoming a decent human being, learning some empathy, and realizing that perhaps other people have used the courts as recourse because they, too, were scr…

Ok, I think you're assigning me to a camp in your head that I do not belong to. I'm not the corporation-loving, lawyer-hating, "tort-reforming" droid you're looking for. If you believe in the rule of law, which I do, then lawsuits are inevitable. There have been great lawsuits in history that have ensured freedom, ended injustice, and punished evil. But there have also been lawsuits used to bully, intimidate, and coerce. I assume you've heard of patent trolls? How about the SCO saga? How about the Scopes Monkey Trial? That's why I said I'm "ambivalent"[1] about them.

[1]http://dictionary.reference.com/browse/ambivalent

Re: Lenovo Statement on Superfish

#276

> Users are not tracked nor re-targeted Have a look at code delivered by Superfish: https://www.superfish.com/ws/sf_preloader.jsp https://www.superfish.com/ws/sf_code.jsp And grep for track and retarget. Just two snippets: var url = sfDomain + "trackSession.action?userid=" + similarproducts.b.qsObj.userid + "&sessionid=-10&action=ud_host_failed"; and: function isRetargetingEnabled(){ if( similarproducts.b.enableRetar…

Outstanding. It's like a ridiculous Law & Order episode where the defendant goes "I wasn't even in town that night." "So what's your face doing on all of these security cameras at the scene of the crime?" "... uh..."

so just to be clear, because I find this hard to believe, they are straight up, 100% lying? Or is this taking some hash generating code out of context or something?

Re: Lenovo Statement on Superfish

#277

> Users are not tracked nor re-targeted Have a look at code delivered by Superfish: https://www.superfish.com/ws/sf_preloader.jsp https://www.superfish.com/ws/sf_code.jsp And grep for track and retarget. Just two snippets: var url = sfDomain + "trackSession.action?userid=" + similarproducts.b.qsObj.userid + "&sessionid=-10&action=ud_host_failed"; and: function isRetargetingEnabled(){ if( similarproducts.b.enableRetar…

Outstanding. It's like a ridiculous Law & Order episode where the defendant goes "I wasn't even in town that night." "So what's your face doing on all of these security cameras at the scene of the crime?" "... uh..."

so just to be clear, because I find this hard to believe, they are straight up, 100% lying? Or is this taking some hash generating code out of context or something?

Re: Lenovo Statement on Superfish

#278

Earlier quoted context omitted.

> Lenovo: One customer lost. More to be lost. Never purchased a Lenovo but I was bent on using one for my next machine. No longer. Their lies about it "not being a risk" have put the affected customers at immense risk.

Doesn't matter what machine you're using if your ISP e.g. Comcast is injecting ads into the web pages you visit!

Yes it does. No Lenovo for me.

Re: Lenovo Statement on Superfish

#279
post #45

Earlier quoted context omitted.

> Can you ever imagine Apple pulling a stunt like this? No Why would you jump to that conclusion? Apple is just a company... and through the right view-port, even something like this can appear to be "consumer oriented" to management ("we're helping customers locate products and services easier"). Recently Canonical thought it was a great idea to bake-in Amazon ads into their search lens... so ads and product placeme…

Apple is definitely not immune to stupid things. They've done a lot of stupid things. Apple have also made tons of mistakes when it comes to security and privacy. But I still have a hard time seeing Apple ever intentionally adding a feature that proxies all a user's encrypted connections to inspect the content and insert ads. Tim Cook's recent speech at the Cybersecurity summit sounded pretty earnest to me https://ww…

Gen. Alexander's talk at Def Con 2012 sounded pretty earnest, too...

Re: Lenovo Statement on Superfish

#280

Earlier quoted context omitted.

I'm on record around here about being angry with Yosemite sending requests off-machine, and it's the first thing I turn off. Lenovo enables anyone, anywhere, to MitM your bank . Difference in kind. Massive, massive difference in kind.

I imagine that whoever made the decision in Lenovo didn't understand that's what they were doing. They heard "(technical jargon)... replaces some adverts on webpages... Profit!" and signed off on it. That's not an excuse for this, but it smells like incompetence rather than deliberate malice (at least on Lenovo's part - Superfish/Komodia may be another story).

I soundly reject the notion that everyone in Lenovo's chain of auditing and implementation just heard "technical jargon". No company is magically and universally nontechnical. And anyone who allowed this to pass and remains employed there is culpable.
Post reply on HN