Live data from Hacker News

Lenovo Caught Installing Adware on New Computers

thenextweb.com

421–430 of 435 posts

Re: Lenovo Caught Installing Adware on New Computers

#421
post #413

Earlier quoted context omitted.

The problem in Lenovo's situation is, calling it incompetence is the real stretch. You could call Charles Manson incompetent saying he just didn't know what he was doing was wrong, but everyone knows he was just evil. Never falsely attribute to incompetence what is actually ascribable to malice. You can't come in here with a straight face and say that no one at Lenovo considered the security risk of including this so…

I don't think anyone there thought/realized that they were including a backdoor usable by any number of third parties (by virtue of installing a mitm-cert, and giving away the key). And this case is much worse than any other crapware-by-way-of-oem than I've heard of. But given the amount of nasty stuff most vendors seem to install on systems -- it appears to me that no one really looks at what is installed, or gives…

But that argument means either that these companies do not have a security team (we know they do), that the security team signed off on this (we know they wouldn't), or the security team raised the risk and management chose to ignore it. There's absolutely no option that says "no one ever thought of this risk", at least not in the world we live in. I've worked in enterprise security and I still work in the security industry. There is just no way that this software got approved to be put in a default install and had no review from the security department.

That's what I meant by invoking the opposite of Hanlon's razor. Sure, never attribute to malice what can be explained by ignorance. But my point is, you can't explain this one with ignorance. There is just no way that Lenovo has hired a security team that would do a review of this and say it looks fine, and no way a company the size and stature of Lenovo would not have a competent security team. The only logical answer is that this was raised as a risk and management chose to accept the risk.

I'm not saying they're evil (I used that word to describe Charles Manson), nor that their end goal was for users to be compromised. Merely that they had to know this was a bad idea, and they chose to do it anyway.

Re: Lenovo Caught Installing Adware on New Computers

#422
post #115
post #94

Earlier quoted context omitted.

but apparently no one did a security review It doesn't take a "security review" to spot a gaping security and privacy violation like this. Any engineer with even the slightest clue of how a browser and "the internet" works would have called this out during the first "How does this product work?"-presentation. Let's not pretend Lenovo is staffed with monkeys.

“Never ascribe to malice that which can adequately be explained by incompetence.” Remember stuff like this: http://www.cryptofails.com/post/70059600123/saltstack-rsa-e-... (Which, possibly unfairly, is one reason I'm leaning more towards ansible than saltstack to this day -- I mean, if stuff like that got through... what else, in more complex areas of the system?)

Never exclusively ascribe either malice or incompetence to explain the actions of a large bureaucracy. It is nearly always both.

Re: Lenovo Caught Installing Adware on New Computers

#423

Earlier quoted context omitted.

the nature of writing a blog post ex post facto?

So, just a hunch that it would be a company name or something else that might be in the dump? There's no technical reason for the actual password itself to somehow end up there? A serious security flaw or something?

What I mean is, we are reading about it because it worked.

It's the lowest hanging fruit. I doubt he expected to find the password just sitting there, but since he did, here we are :)

But yes, keeping sensitive information hidden in plain text considered a security flaw.

Re: Lenovo Caught Installing Adware on New Computers

#424
post #126

Ugh. So for "developer-tier" laptops, i.e. not a netbook, does that pretty much leave Apple as the sole non-shit laptop maker? Is there a chromebook out there that runs linux pretty well if you pull chromeOS off? You pay a hefty premium for that backlit Apple logo on the lid, and I'd prefer to get something a little more down-to-earth.

I used to love Dell's Precision laptops.

Precision M4800, for example.

15", i7-4710MQ, Nvidia Quadro K100M 2GB, 4K screen, AC wireless, 512GB SSD for around $2500, about similar to the high end rMBP 15" (yes, I know there are things the rMBP has, just as there are things the Precision has - it's 'comparable', not 'identical').

Re: Lenovo Caught Installing Adware on New Computers

#425
post #413

Earlier quoted context omitted.

I don't think anyone there thought/realized that they were including a backdoor usable by any number of third parties (by virtue of installing a mitm-cert, and giving away the key). And this case is much worse than any other crapware-by-way-of-oem than I've heard of. But given the amount of nasty stuff most vendors seem to install on systems -- it appears to me that no one really looks at what is installed, or gives…

But that argument means either that these companies do not have a security team (we know they do), that the security team signed off on this (we know they wouldn't), or the security team raised the risk and management chose to ignore it. There's absolutely no option that says "no one ever thought of this risk", at least not in the world we live in. I've worked in enterprise security and I still work in the security i…

You may be right. I'm inclined to believe the provisioning team in Lenovo is understaffed, and that they don't really do much security analysis at all. So I believe their negligent, and that their process is negligent. But I'm open to the idea that I might very well be wrong about that. Either way, it doesn't speak very highly of what kind of quality one can expect to get when shopping Lenovo products.

Re: Lenovo Caught Installing Adware on New Computers

#426
My dad saw this post and asked that I post the following here for him. He didn't want to make an account:

"Why do it if you are Lenovo? Well it seems clear to me that there was a financial inducement provided by superfish. I mean Lenovo is not loading software unless they are financially benefited. Come on.

As far as other inducements go, consider this. Two weeks ago I got an expensive, new Lenovo machine. Got it running just fine, thank you, and then I download Chrome from what was very, very clearly identified as google.com. Who do you trust man. Fired it up and immediately my machine locked me out and became unresponsive. Called Lenovo and for $200 worth of Lenovo.premiumsupport they fixed it and gave me 10 months of additional support. $20/month for 10 months on top of a normal laptop margin does not provide much of an inducement to cease and desist."

Re: Lenovo Caught Installing Adware on New Computers

#427
post #121

Hopefully Redmond will give hell to Lenovo for this. Also, apparently this is just the start for crapware on new PCs - Paul Thurrott said on the podcast Windows Weekly about a week ago that crapware is going to get a lot worse this PC cycle.

> Paul Thurrott said on the podcast Windows Weekly about a week ago that crapware is going to get a lot worse this PC cycle.

Did he say why?

Re: Lenovo Caught Installing Adware on New Computers

#428

Earlier quoted context omitted.

Wow, really? I never knew that and some googling didn't find any decent sources. do you have one?

https://developer.chrome.com/multidevice/data-compression

Many thanks, easy when you know the right keywords >.<

Re: Lenovo Caught Installing Adware on New Computers

#430

Earlier quoted context omitted.

Do you trust a hardware vendor that installs MITM stuff on your machine per default to keep the firmware untampered? There is almost no machine out there running openly auditable code on all components.

So what? At least with the software part you remove a large portion of the risks. It's better to go half way than doing nothing about it, and hardware tampering for a company could be more risky since they would have to do mass recall if discovered.

I'm talking Firmware-tampering, which is rather risk-free and firmware patches are not unusual.
Post reply on HN