Live data from Hacker News

Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

wired.com

31–40 of 225 posts

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#31
post #16

"Beijing-based computer maker Lenovo has reportedly been blacklisted for years by spy agencies worldwide, as concerns about government-sanctioned Chinese hacking persist. According to the Australian Financial Review, Australia, the UK, Canada, New Zealand, and the US have all rejected Lenovo machines for their top-secret networks since the mid-2000s, though the computers can be used for lower-security tasks that don'…

Superfish is a US company, though, and Komodia is Israel based.

There is nothing connecting this to the Chinese government. This appears to be a a cross-border display of greed and incompetence.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#32
post #16

"Beijing-based computer maker Lenovo has reportedly been blacklisted for years by spy agencies worldwide, as concerns about government-sanctioned Chinese hacking persist. According to the Australian Financial Review, Australia, the UK, Canada, New Zealand, and the US have all rejected Lenovo machines for their top-secret networks since the mid-2000s, though the computers can be used for lower-security tasks that don'…

This seems offtopic unless you think the recent security lapse was some type of conspiracy instead of just apathy, greed, and incompetence.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#33
post #12

I was under the impression that Lenovo supplies a lot of computers to government and enterprise contracts around the world. Was Superfish only installed on consumer oriented devices, like the ones typically found at Best Buy? I realize most large enterprise would re-image their computers before deployment. I'm shocked that Lenovo would release such a statement. The damage to its credibility is significant.

Yes, it was only installed on their consumer oriented machines. Their T model Thinkpad don't have it installed.

Now the question is of course what else are they installing and what other yet undiscovered issues we'll find. It sounds like FUD but so far based on their response, they seem either incompetent (stupid) or malicious. And I don't exactly like either...

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#34
post #13

Microsoft is currently doing Lenovo's work for them: https://twitter.com/FiloSottile/status/568800260111388672 The latest version of Windows Defender is actively removing the Superfish software and the cert. The text of the definition is here: http://pastebin.com/raw.php?i=us7iXvkn

15 years ago this would have led to rioting on slashdot and Usenet. How dare Microsoft remove someone else's software? I'm generally in favor of MS doing this specific thing, but there is potential for abuse here.

No 15 years ago Microsoft would have been the ones installing it.

I think Microsoft went from being a hated software giant to sort of an underdog vis-a-vis Google, Facebook, Amazon and Apple.

They are very big and strong no doubt, but I think the attitude they are projecting since switching CEO recently, their open source efforts, and such make them look pretty good PR-wise among the tech crowd.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#35
post #13

Microsoft is currently doing Lenovo's work for them: https://twitter.com/FiloSottile/status/568800260111388672 The latest version of Windows Defender is actively removing the Superfish software and the cert. The text of the definition is here: http://pastebin.com/raw.php?i=us7iXvkn

15 years ago this would have led to rioting on slashdot and Usenet. How dare Microsoft remove someone else's software? I'm generally in favor of MS doing this specific thing, but there is potential for abuse here.

They are not removing someone else's software though, they are alerting you to a security issue, recommending removal, and providing the tools to do so. That's exactly what an antivirus is supposed to do.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#36

The more they deny this is a problem, the more it damages their reputation. They should just admit the problem, thank the security experts, and develop an easy fix.

They did admit the problem and linked page describing how to remove SuperFish.

> We're sorry. We messed up. We're owning it. And we're making sure it never happens again. Fully uninstall Superfish: http://lnv.gy/182BW8g

https://twitter.com/lenovoUS/status/568578319681257472

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#37

I warned all my friends and colleagues who use Lenovos, and their answers were all the same. "Who'd be crazy enough to use the default install? First thing I did was (a fresh reinstall of Windows|install Linux)." (Edit: Obviously this is not representative of the general population, and I didn't mean to suggest it was. I was just noting that my efforts to warn people about the untrustworthiness of Lenovo were thwarte…

The CD for the clean install is included in the Home versions? Interesting.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#38
post #13

Microsoft is currently doing Lenovo's work for them: https://twitter.com/FiloSottile/status/568800260111388672 The latest version of Windows Defender is actively removing the Superfish software and the cert. The text of the definition is here: http://pastebin.com/raw.php?i=us7iXvkn

Every AV should be doing this. Is MS the only one doing it?

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#39

While we're at it, Lenovo's statement that we might enjoy the adware: "The relationship with Superfish is not financially significant; our goal was to enhance the experience for users" is self-evidently bullshit.

The key word is significant. They're not claiming they didn't preload this software for money, they're just saying it wasn't for very much money. Such a small amount of money that they have no problem ending the relationship now that it's causing them problems.

My wild guess would be they got in the ballpark of $0.25 an install.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#40
post #28
post #16

"Beijing-based computer maker Lenovo has reportedly been blacklisted for years by spy agencies worldwide, as concerns about government-sanctioned Chinese hacking persist. According to the Australian Financial Review, Australia, the UK, Canada, New Zealand, and the US have all rejected Lenovo machines for their top-secret networks since the mid-2000s, though the computers can be used for lower-security tasks that don'…

Why buy a computer from a company that has ties to the US government, an authoritarian government that supports dictators in Africa, the Middle-East, South America, and East Asia, including torture, drug smuggling, misogyny, and has itself engaged in abduction, detention without trial, and in relation to this case, illegal interception of communications?

1.) Which US computer company has ties to US government? Literally owned by the government?

2.) How is US government authoritarian? Have you actually lived in a country that has no elected representative?

Post reply on HN