Live data from Hacker News

Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

wired.com

191–200 of 225 posts

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#191
post #88

I warned all my friends and colleagues who use Lenovos, and their answers were all the same. "Who'd be crazy enough to use the default install? First thing I did was (a fresh reinstall of Windows|install Linux)." (Edit: Obviously this is not representative of the general population, and I didn't mean to suggest it was. I was just noting that my efforts to warn people about the untrustworthiness of Lenovo were thwarte…

I'm on my 4th Thinkpad. I always do a fresh install of Linux, would never trust the pre-installed crap. But now that I know that Lenovo is a piece of shit company with zero integrity, I don't even want to trust their hardware.

I despise Lenovo. Purely from an engineering quality aspect, they aren't remotely close to IBM. I've been on the T440p for a year now, and I utterly hate using it. Every time I'm not docked, I'm really, really, annoyed. (Compared to feeling great when on the X201.)

But what am I gonna do? There's essentially no options to replace an old X-style ThinkPad. The newest Carbon X1 is as close as anything. Everyone else is moving to the Apple-style clickpad, which is unacceptable. HP and Dell sell mostly crap. Apple's devices are hot and unergonomic (apart from questionable Windows driver support).

So good luck not trusting them. And I doubt HP'd do any better.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#192
post #39

While we're at it, Lenovo's statement that we might enjoy the adware: "The relationship with Superfish is not financially significant; our goal was to enhance the experience for users" is self-evidently bullshit.

The key word is significant . They're not claiming they didn't preload this software for money, they're just saying it wasn't for very much money. Such a small amount of money that they have no problem ending the relationship now that it's causing them problems. My wild guess would be they got in the ballpark of $0.25 an install.

I'm not even that miffed about being a product and not the customer; I am incredibly miffed that I'm apparently one of the products in the discount bin.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#193
post #13

Microsoft is currently doing Lenovo's work for them: https://twitter.com/FiloSottile/status/568800260111388672 The latest version of Windows Defender is actively removing the Superfish software and the cert. The text of the definition is here: http://pastebin.com/raw.php?i=us7iXvkn

As well Microsoft should be.

Its brand is as tarnished (if not more so) by this sort of crap.

Not that Microsoft's own hands are clean or that the issue of crapware preloads isn't a massive problem.

Google should also be paying attention: Android preloads are also increasingly a massive turn-off.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#194

Can someone explains to me how Graham claims he can decrypt the intercepted traffic? The proxy communicates securely with the intended website. It's just the browser proxy communication that's vulnerable but that's local on the machine, no ?

I'm wondering the same thing. As far as I understand, the proxy is local to the machine, so HTTPS traffic over Wi-Fi should be past the proxy and therefore encrypted using the real certificate.

The proxy accepts fake certificates so you can MiTM anyone. It does not properly verify the remote site's certificate.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#195

Earlier quoted context omitted.

I'm wondering the same thing. As far as I understand, the proxy is local to the machine, so HTTPS traffic over Wi-Fi should be past the proxy and therefore encrypted using the real certificate.

The installed backdoor certificate is trusted as a root certificate. Its private key is contained in the MITM software, and is now known publicly. So anyone can now create phony certs signed by the backdoor cert, and Lenovo machines accept them as valid. Here is such a page: https://badfish.filippo.io/yes.png That's an image of the word "Yes" signed with the Superfish certificate. If your browser shows that image wit…

Right but this only means you can decrypt data coming from websites using a starfish cert. It doesn't mean you can decrypt your bank traffic because you have this proxy installed which is what Graham is claiming.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#196
post #111

Earlier quoted context omitted.

The OED says: > Favourable to or characterized by obedience to authority as opposed to personal liberty; strict, dictatorial. It's certainly reasonable to argue about whether this actually applies; but I don't think that it represents a useless dilution of the word to think that it might. (Well, not 'dictatorial', but the rest of it.)

I'd like to hear that argument and not just the assertion that it is arguable.

Actually I meant by

> It's certainly reasonable to argue about whether this actually applies

literally that it is reasonable to argue, i.e., that neither position is obviously irrefutably true; and also I think I've created enough of a de-rail already here; but, if I had to make an argument for authoritarianism, I think that I would claim that the concept of free-speech zones instantly implies, for some parts of US government at some times, more respect for authority than personal liberty.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#197

Earlier quoted context omitted.

I didn't ask them. Maybe piracy + "I have a Windows license so it's ok-ish" rationalization.

Piracy is hardly a "clean install". I wouldn't be surprised if a decent-sized number of the bootleg Windows installs out there are heavily-rootkitted. I haven't seen any recent statistics, but at one point, 74% of rootkit infections were on pirated copies of Windows XP [0] [0] http://www.zdnet.com/article/study-rootkits-target-pirated-c...

I think that this may actually be attributed to the lack of working Windows Update on a lot of pirated systems.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#199
post #197

Earlier quoted context omitted.

Piracy is hardly a "clean install". I wouldn't be surprised if a decent-sized number of the bootleg Windows installs out there are heavily-rootkitted. I haven't seen any recent statistics, but at one point, 74% of rootkit infections were on pirated copies of Windows XP [0] [0] http://www.zdnet.com/article/study-rootkits-target-pirated-c...

I think that this may actually be attributed to the lack of working Windows Update on a lot of pirated systems.

Yes and no. There is at least one case that I can remember[0] of pirated software being modified to download and install a virus.

According to Microsoft[1], 32% of pirated Windows 7 copies and activation cracks resulted in some sort of malware infection

Speaking anecdotally, most of the friends and family whose computers I've had to clean up have been running some sort of cracked/pirated software that they'd downloaded or had been given to them by a friend

[0] http://voices.washingtonpost.com/securityfix/2009/05/pirated...

[1] Admittedly, Microsoft has somewhat of a bias, but the number sounds reasonable to me: http://archive.news.softpedia.com/news/32-of-Pirated-Windows...

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#200
post #13

Microsoft is currently doing Lenovo's work for them: https://twitter.com/FiloSottile/status/568800260111388672 The latest version of Windows Defender is actively removing the Superfish software and the cert. The text of the definition is here: http://pastebin.com/raw.php?i=us7iXvkn

15 years ago this would have led to rioting on slashdot and Usenet. How dare Microsoft remove someone else's software? I'm generally in favor of MS doing this specific thing, but there is potential for abuse here.

Sorry, but as one who was on Slashdot from pre-userid days, and is in general a huge critic of the company, bullshit.

Microsoft is in a hard place in terms of determining what is or isn't allowed on their systems (due in large part to their own past and quite probably ongoing monopoly abuses), but fixing obvious flaws is to be applauded.

I don't champion the company often, but they're doing the right thing here. Actually, sanctioning Lenovo for letting this happen might be another option they've got. Though something tells me they won't play that card (and quite possibly cannot).

Post reply on HN