Live data from Hacker News

Lenovo Statement on Superfish

news.lenovo.com

291–300 of 312 posts

Re: Lenovo Statement on Superfish

#291
post #4

> We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns. I try to be measured around here, as hard as I can. I can't formulate a polite way to respond to this claim. Lenovo, you are full of shit, and maliciously so. There is no excuse, nor forgiveness, for what you've done here.

It's quite possible that the muckety-mucks who signed off on this in the first place were unaware of the implications. But at this point, the technical details should be known even to the clueless pointy-hair types.

It's probable that their lawyers told them to make this claim to lessen their exposure to lawsuits. If they admitted any kind of problem they'd be in hot water, but now the burden is on anyone bringing a suit to prove them wrong.

The first thing we do, let's kill all the lawyers.

Re: Lenovo Statement on Superfish

#292
post #175

Earlier quoted context omitted.

I love my Lenovo X1 Carbon. It's a really nice machine. I do run linux so I know I'm not the average user, but they haven't lost my business despite this being an epic screw-up. I think they make good machines and I'll continue to buy from them in the future, but I'll be reformatting immediately just like I've always done with any PC I've ever bought from Dell, Gateway, Lenovo, etc, so I don't have to deal with the b…

If they are willing to compromise you on a software level, what makes you think they aren't prepared to do so on the hardware level (presuming they already aren't).

In a company as big as Lenovo, I'd be kind of surprised if the person or persons who decide what bloatware to load onto the consumer image make any sort of hardware decisions.

There's also that this particular kind of compromise is basically inapplicable to hardware. What are they going to do, put a 3G radio in your laptop that broadcasts your "data" via the cell network to Belarus?

Re: Lenovo Statement on Superfish

#293
post #4

> We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns. I try to be measured around here, as hard as I can. I can't formulate a polite way to respond to this claim. Lenovo, you are full of shit, and maliciously so. There is no excuse, nor forgiveness, for what you've done here.

It seems they have removed this statement completely. Unless you meant here: http://forums.lenovo.com/t5/Lenovo-P-Y-and-Z-series/Removal-...

Re: Lenovo Statement on Superfish

#294

Earlier quoted context omitted.

> When you catch somebody misbehaving, and their response is "fine, I'll stop, but it wasn't a problem" then you can't trust them at all. Indeed. This kind of response is one of the most disrespectful things you can do to another person. "Hey, what are so upset about? Chill, it wasn't a big deal anyway!"

I'm kind of impressed that their PR guys are so incompetent. Their statement is so nakedly condescending, they might as well have straight-up said, "You guys are full of shit, but we'll stop just so you'll shut up about it."

If I was a lawyer, the basic requirement I'd have for a statement like this is to make it so it can't be construed as an admission of guilt, because that may later be used in court to extract damages.

You probably should blame legal, not PR.

Re: Lenovo Statement on Superfish

#295
post #175

Earlier quoted context omitted.

If they are willing to compromise you on a software level, what makes you think they aren't prepared to do so on the hardware level (presuming they already aren't).

In a company as big as Lenovo, I'd be kind of surprised if the person or persons who decide what bloatware to load onto the consumer image make any sort of hardware decisions. There's also that this particular kind of compromise is basically inapplicable to hardware. What are they going to do, put a 3G radio in your laptop that broadcasts your "data" via the cell network to Belarus?

This provides some details :

http://thehackernews.com/2015/02/hard-drive-firmware-hacking...

So no, they'll get a rootkit process running on your machine and (for instance) upload everything on your hard drive through your web browser.

Another thing they've done is to upload hacked drivers to cause other hardware connected to the infected machine to physically destroy itself.

Re: Lenovo Statement on Superfish

#296
post #294

Earlier quoted context omitted.

I'm kind of impressed that their PR guys are so incompetent. Their statement is so nakedly condescending, they might as well have straight-up said, "You guys are full of shit, but we'll stop just so you'll shut up about it."

If I was a lawyer, the basic requirement I'd have for a statement like this is to make it so it can't be construed as an admission of guilt, because that may later be used in court to extract damages. You probably should blame legal, not PR.

I'm certain that the legal requirements can be met without outright lying (or admitting to unbelievably gross incompetence).

In fact, they seem to agree. I loaded the page just now, and "We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns." is no longer present in their statement.

Their statement is still unbelievably condescending and awful (and none of that has any legal bearing that I can see) but they at least removed the part where they outright denied any security problem.

Re: Lenovo Statement on Superfish

#297
post #282
post #275

Earlier quoted context omitted.

Ok, I think you're assigning me to a camp in your head that I do not belong to. I'm not the corporation-loving, lawyer-hating, "tort-reforming" droid you're looking for. If you believe in the rule of law, which I do, then lawsuits are inevitable. There have been great lawsuits in history that have ensured freedom, ended injustice, and punished evil. But there have also been lawsuits used to bully, intimidate, and coe…

All of the above are a vast minority of lawsuits, and I read ambivalence as functionally equivalent to anti-tort. Again, you were ambivalent until your ox got gored.

You might have withheld your hostility if you had first double-checked the definition of "ambivalent".

It does not mean or imply "opposed" or "disdainful" or "disinterested", at all.

Re: Lenovo Statement on Superfish

#298
post #281

Earlier quoted context omitted.

This is totally correct - I just meant that using Lenovos provided installation media would not resolve the issue. You can definitely use an OEM disk of your exact version with your printed serial. I too have had to procure new keys for win8 machines (did two last week that wouldn't recognize the keys on my machine)

Windows Vista and up did away with special OEM ISO/Disks. You can use your OEM license with any official ISO/Disk. What you may of had issue with was your OEM license being activated too many times -- if that happens, the automatic online activation will not work. You must use the phone number to activate your license, and it will ask "how many computers is this license installed on"... of course you just give the an…

"Windows Vista and up did away with special OEM ISO/Disks. You can use your OEM license with any official ISO/Disk."

Are you referring to all flavors(Home Basic/Home Premium/Pro/Ultimate) from one disk? Installing retail/OEM from one disk has never been the case in my experience, though I have limited experience with 'retail' installs. I joined TechNet ~6 years back to obtain ISOs to reload various x32/x64/Vista/7 installs, but none of the machines' OEM keys I tried would work with the TN ISO's. If I'm not mistaken, they were specifically 'retail' ISOs.

Re: Lenovo Statement on Superfish

#299

Earlier quoted context omitted.

I'd argue that so far, that's exactly the point, their response makes it worse. "We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns" is a laughable statement to have issued. I can understand the legal reasons for not admitting to the security issues. But outright saying that they can't find anything to suggest they exist indicates a company I wouldn't want t…

I also had to laugh when Jobs started talking about "antenna gate". Instead of saying "We made a mistake here" he started saying "other phones have similar problems", etc. So his response wasn't good, but people still buy Apple and Apply is currently the largest company by market cap...

An antenna doesn't pose a security hole. Bullshit about antennas in other phones is Apple's traditional humbleness deficit, bullshit about compromised SSL connections is a criminal lie.

Re: Lenovo Statement on Superfish

#300
post #4

> We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns. I try to be measured around here, as hard as I can. I can't formulate a polite way to respond to this claim. Lenovo, you are full of shit, and maliciously so. There is no excuse, nor forgiveness, for what you've done here.

Indeed. I have been buying IBM and then Lenovo Thinkpads for ages. I hate the thought that my next machine will be another brand. Lenovo: One customer lost. More to be lost.

This actually never affected Thinkpads.
Post reply on HN