Live data from Hacker News

Lenovo Caught Installing Adware on New Computers

thenextweb.com

411–420 of 435 posts

Re: Lenovo Caught Installing Adware on New Computers

#411
post #204

This is why I do a flat install on every new machine I get. Also, why are we bitching just at Lenovo. There are software developers out there writing this shit. Name and shame the companies and staff. There needs to be a no hire and no do business with list. Ethics go all the way down. I'm rather disappointed though as I've recommended Lenovo hardware recently to people and use an X201 myself.

If a guy is demonstrably capable of writing malware, and we all refuse to hire him to do anything else, he will probably write more malware rather than starve.

Re: Lenovo Caught Installing Adware on New Computers

#412
post #383

Earlier quoted context omitted.

So because a few people decide to cheat at a game they paid for, everyone who paid full price for the game is forced to install spyware which can and does modify files on your pc, take screenshots as you play the game, monitor your mouse inputs, keyboard, etc...?

I think that is fine, personally. Obviously others might not. You have to specifically agree to install/allow PunkBuster, and you can choose to play on servers that don't use PunkBuster. With Lenovo not only is there no opt-out, but you're not even aware of the adware and root CA installation. The "spyware" only spies on modifications to the game client in any way and tries to detect non-human involvement, which of c…

It's not fine because, as is the case with Superfish, this type of software leaves gaping security holes that blackhats can exploit no matter how noble the vendor is.

Re: Lenovo Caught Installing Adware on New Computers

#413
post #115

Earlier quoted context omitted.

“Never ascribe to malice that which can adequately be explained by incompetence.” Remember stuff like this: http://www.cryptofails.com/post/70059600123/saltstack-rsa-e-... (Which, possibly unfairly, is one reason I'm leaning more towards ansible than saltstack to this day -- I mean, if stuff like that got through... what else, in more complex areas of the system?)

The problem in Lenovo's situation is, calling it incompetence is the real stretch. You could call Charles Manson incompetent saying he just didn't know what he was doing was wrong, but everyone knows he was just evil. Never falsely attribute to incompetence what is actually ascribable to malice. You can't come in here with a straight face and say that no one at Lenovo considered the security risk of including this so…

I don't think anyone there thought/realized that they were including a backdoor usable by any number of third parties (by virtue of installing a mitm-cert, and giving away the key). And this case is much worse than any other crapware-by-way-of-oem than I've heard of. But given the amount of nasty stuff most vendors seem to install on systems -- it appears to me that no one really looks at what is installed, or gives much thought to the consequences.

It's negligent, and in this case probably criminally so -- and that might constitute "an evil" -- but I don't think this is the result of someone's overt intentional evil act. I don't think anyone actually did consider the security risk of this particular piece of software. Maybe I'm naive, but if nothing else, the risk of lawsuits/backlash seems too great in this case.

I don't like ads and bloatware, but I think calling them "evil" is diluting what "evil" means.

I might be wrong, of course. But I don't think any of the big OEMs does any real review of the crap that is installed on computers -- and I think forgetting to generate an unique cert/key on post-install/first run is an error -- not intentional. Deciding to install this kind of crap strikes me as a very poor decision -- but I'm still not sure I'd consider it evil. Evil would be using the Intel management co-prosessor to do something similar -- presumably then a clean install wouldn't help.

Re: Lenovo Caught Installing Adware on New Computers

#414
post #329

Earlier quoted context omitted.

Impersonating a CA is not transparent and risks losing that CA if anyone finds out it's forging certs. They probably can do that, but it's a risky nuclear option. This is a transparent dragnet that can easily be blamed away, which has been shown to be much more preferable in the NSA's M.O.

The sad thing is we don't need to invoke the big bad NSA here. There is absolutely positively nothing about this that suggests it is anything other than bog-standard SSL incompetence. And to be clear, I mean, absolutely nothing. This isn't a slightly unlikely thing that still leaves room to wonder about "plausible deniability"... this is a thing that happens all the damned time and the NSA need at most sit back and p…

It does seem like this is more of an amateur hour screw-up. It isn't beyond the NSA to plant developers that can insert backdoors on their behalf or set up front companies to sell vulnerable libraries but one would hope that they have enough sense not to leave cleartext passwords in a binary. Of course that could be an intentional misdirection so one never really knows.

Re: Lenovo Caught Installing Adware on New Computers

#415
post #88

Earlier quoted context omitted.

Are you sure? Android Chrome proxies all non-HTTPS traffic through a third-party server, by default. So it isn't like the traffic volume is impossible.

Yes but that's Google. I'd be surprised if Superfish had resources like that, or could generate that much traffic from their servers and not be noticed (by, say, Google). I could be wrong.

Superfish might have "benefactors" with deep pockets who want a scapegoat who won't squeal on them.

Re: Lenovo Caught Installing Adware on New Computers

#416

Earlier quoted context omitted.

The T420 is, in my opinion, the last known good computer that Lenovo put out. I bought one in 2011 and still use it (sparingly) today. That is a rock solid laptop with a fantastic touchpad/keyboard. We bought T440s a year or two later and both were just abysmal. The trackpad, the keyboard, everything is crappy and fails to work properly. No one at our company would use them and they sit in a closet now. I've been mon…

You will find a lot of people who say things like: The [insert laptop model here] is, in my opinion, the last known good computer that [insert laptop brand here] put out. In the end it's just that, a personal opinion. I have read similar things about basically every laptop(heck even cars, TVs, Fridges) brand in existence.

What was the point of this comment? I said in the first line it was my opinion.

Re: Lenovo Caught Installing Adware on New Computers

#417
post #204

This is why I do a flat install on every new machine I get. Also, why are we bitching just at Lenovo. There are software developers out there writing this shit. Name and shame the companies and staff. There needs to be a no hire and no do business with list. Ethics go all the way down. I'm rather disappointed though as I've recommended Lenovo hardware recently to people and use an X201 myself.

If a guy is demonstrably capable of writing malware, and we all refuse to hire him to do anything else, he will probably write more malware rather than starve.

Interesting and well thought out point.

Re: Lenovo Caught Installing Adware on New Computers

#420
post #204

This is why I do a flat install on every new machine I get. Also, why are we bitching just at Lenovo. There are software developers out there writing this shit. Name and shame the companies and staff. There needs to be a no hire and no do business with list. Ethics go all the way down. I'm rather disappointed though as I've recommended Lenovo hardware recently to people and use an X201 myself.

Komodia seems to be a good guess on the question of which company.
Post reply on HN