Live data from Hacker News

Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

wired.com

181–190 of 225 posts

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#181

Earlier quoted context omitted.

It's not, but you don't need one. You can make your own disk or USB pretty easily: http://windows.microsoft.com/en-us/windows-8/create-reset-re...

This is one of the things that Microsoft gets right, that I wish Apple would do better.

With Macs you have multiple options. The first being much easier than a typical Windows PC.

1) Boot into Recovery mode (Cmd + R), then use Internet Recovery [1] to install OS X. This works even if your HDD or SSD is completely blank. All Macs from around mid-2010 onwards are supported. [2]

2) Download the latest OS X installer from the Mac App Store, then either use the bundled 'createinstallmedia' command-line app to create a bootable USB flash drive [2] or a third-party app called DiskMaker X [3].

[1] http://support.apple.com/en-gb/HT4718

[2] http://support.apple.com/en-gb/HT202313

[3] http://support.apple.com/en-gb/HT201372

[4] http://liondiskmaker.com/

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#182
post #65
post #16

"Beijing-based computer maker Lenovo has reportedly been blacklisted for years by spy agencies worldwide, as concerns about government-sanctioned Chinese hacking persist. According to the Australian Financial Review, Australia, the UK, Canada, New Zealand, and the US have all rejected Lenovo machines for their top-secret networks since the mid-2000s, though the computers can be used for lower-security tasks that don'…

I'd be curious to know what brands or models are considered safe by these agencies.

hp

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#183
post #65
post #16

"Beijing-based computer maker Lenovo has reportedly been blacklisted for years by spy agencies worldwide, as concerns about government-sanctioned Chinese hacking persist. According to the Australian Financial Review, Australia, the UK, Canada, New Zealand, and the US have all rejected Lenovo machines for their top-secret networks since the mid-2000s, though the computers can be used for lower-security tasks that don'…

I'd be curious to know what brands or models are considered safe by these agencies.

hp

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#184

Can someone explains to me how Graham claims he can decrypt the intercepted traffic? The proxy communicates securely with the intended website. It's just the browser proxy communication that's vulnerable but that's local on the machine, no ?

I'm wondering the same thing. As far as I understand, the proxy is local to the machine, so HTTPS traffic over Wi-Fi should be past the proxy and therefore encrypted using the real certificate.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#185
post #72
post #34

Earlier quoted context omitted.

No 15 years ago Microsoft would have been the ones installing it. I think Microsoft went from being a hated software giant to sort of an underdog vis-a-vis Google, Facebook, Amazon and Apple. They are very big and strong no doubt, but I think the attitude they are projecting since switching CEO recently, their open source efforts, and such make them look pretty good PR-wise among the tech crowd.

Microsoft has done some shady things, but at no time in Microsoft's history would they have installed this.

You should look into some of the stuff MS did in the glory years, such as deliberately breaking rival software from Lotus, Borland, and Apple.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#186
post #65
post #16

"Beijing-based computer maker Lenovo has reportedly been blacklisted for years by spy agencies worldwide, as concerns about government-sanctioned Chinese hacking persist. According to the Australian Financial Review, Australia, the UK, Canada, New Zealand, and the US have all rejected Lenovo machines for their top-secret networks since the mid-2000s, though the computers can be used for lower-security tasks that don'…

I'd be curious to know what brands or models are considered safe by these agencies.

I think it mentions in the article about agencies having Dell and HP on the list of allowed companies.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#187

Earlier quoted context omitted.

On that note, Microsoft seem to have taken down the windows digital downloads, OEM CD keys don't work. How would you do a fresh install now?

I didn't ask them. Maybe piracy + "I have a Windows license so it's ok-ish" rationalization.

Piracy is hardly a "clean install". I wouldn't be surprised if a decent-sized number of the bootleg Windows installs out there are heavily-rootkitted.

I haven't seen any recent statistics, but at one point, 74% of rootkit infections were on pirated copies of Windows XP [0]

[0] http://www.zdnet.com/article/study-rootkits-target-pirated-c...

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#188

Can someone explains to me how Graham claims he can decrypt the intercepted traffic? The proxy communicates securely with the intended website. It's just the browser proxy communication that's vulnerable but that's local on the machine, no ?

I'm wondering the same thing. As far as I understand, the proxy is local to the machine, so HTTPS traffic over Wi-Fi should be past the proxy and therefore encrypted using the real certificate.

The installed backdoor certificate is trusted as a root certificate. Its private key is contained in the MITM software, and is now known publicly. So anyone can now create phony certs signed by the backdoor cert, and Lenovo machines accept them as valid.

Here is such a page:

https://badfish.filippo.io/yes.png

That's an image of the word "Yes" signed with the Superfish certificate. If your browser shows that image without warnings about an invalid cert, the backdoor exists.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#189

Earlier quoted context omitted.

Lenovo does this for you with their system updater. It downloads and updates all drivers for your system, including bios updates and configuration tweaks that affect power and stability. It will install on a fresh install from Microsoft media - ie there is no need to keep what was preinstalled on the system. http://support.lenovo.com/us/en/documents/ht080136

I don't use those because i don't trust the manufacturer-provided "system updater" to only download drivers. What's to prevent them from surreptitiously installing their add-on garbage. Even if it currently does not do that, I just don't trust it to not do that in general.

Here's a fun surprise: Microsoft allows driver vendors to ship arbitrary programs in addition to drivers. They will download and install these programs automatically. For instance, I bought some "gamer" mouse because it was the closest thing to an Intellimouse 3 I could find. Suddenly I have a \Program Files\Razer directory, and a popup on install telling me to register and do all this other stuff.

So if Lenovo was evil, they can just ship shit in their drivers, get it certified by MS, and have it distributed automatically by Windows Update driver install.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#190

Earlier quoted context omitted.

Is it a Thinkpad, or a consumer model? The Thinkpads were never involved in this.

Well, given that they are morally corrupt enough to do this to their customers, why not expect them to have similar trojans or backdoors on Thinkpads? If we assume firmware is safe, wipe it and do a clean install from trusted media.

Because the business and consumer teams at Lenovo are largely separate. I can't order a Yoga through my Thinkpad rep. I have to go to a retail vendor and us a credit card. I expect there are lots of people at the old IBM offices in New York who are as horrified as we are at when the consumer team agreed to.
Post reply on HN