Live data from Hacker News

Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

wired.com

201–210 of 225 posts

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#201
post #72
post #34

Earlier quoted context omitted.

No 15 years ago Microsoft would have been the ones installing it. I think Microsoft went from being a hated software giant to sort of an underdog vis-a-vis Google, Facebook, Amazon and Apple. They are very big and strong no doubt, but I think the attitude they are projecting since switching CEO recently, their open source efforts, and such make them look pretty good PR-wise among the tech crowd.

Microsoft has done some shady things, but at no time in Microsoft's history would they have installed this.

NSAKEY ...

Though I believe virtually all preloads were OEM actions, not Microsoft's directly.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#202

While we're at it, Lenovo's statement that we might enjoy the adware: "The relationship with Superfish is not financially significant; our goal was to enhance the experience for users" is self-evidently bullshit.

I wonder if this is actually true at all? I mean, yes, everyone around here absolutely abhors software like this, but there is a class of people who love hunting for bargains and accumulating coupons etc. Is there someone who buys a laptop like this and enjoys the additional advertisements? I always wondered the same about those annoying toolbars, I imagine some people actually perceive these as useful.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#203
post #72

Earlier quoted context omitted.

Microsoft has done some shady things, but at no time in Microsoft's history would they have installed this.

NSAKEY ... Though I believe virtually all preloads were OEM actions, not Microsoft's directly.

NSAKEY don't count either.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#204

Earlier quoted context omitted.

I'm wondering the same thing. As far as I understand, the proxy is local to the machine, so HTTPS traffic over Wi-Fi should be past the proxy and therefore encrypted using the real certificate.

The proxy accepts fake certificates so you can MiTM anyone. It does not properly verify the remote site's certificate.

Yes, but MiTM isn't the same as sniffing packets over a wifi in a cafe, which what Graham claimed.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#205

Earlier quoted context omitted.

The proxy accepts fake certificates so you can MiTM anyone. It does not properly verify the remote site's certificate.

Yes, but MiTM isn't the same as sniffing packets over a wifi in a cafe, which what Graham claimed.

If you can read (sniff) WiFi in a cafe, you can write (MiTM), so the difference isn't really important, is it?

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#206
post #77
post #39

Earlier quoted context omitted.

The key word is significant . They're not claiming they didn't preload this software for money, they're just saying it wasn't for very much money. Such a small amount of money that they have no problem ending the relationship now that it's causing them problems. My wild guess would be they got in the ballpark of $0.25 an install.

Which kinda sounds even worse. It says essentially that they're willing to break critical security components on their entire product line for pennies per device. Hey Lenovo, can you install this root cert I made on your entire product line for me? I'll give you like $20 for it. It's at least better than Superfish - I promise not to include the private key with a trivially-crackable password in the install, so only I…

I think it's more likely they don't thoroughly audit every piece of crapware they allow to install.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#207

Earlier quoted context omitted.

The installed backdoor certificate is trusted as a root certificate. Its private key is contained in the MITM software, and is now known publicly. So anyone can now create phony certs signed by the backdoor cert, and Lenovo machines accept them as valid. Here is such a page: https://badfish.filippo.io/yes.png That's an image of the word "Yes" signed with the Superfish certificate. If your browser shows that image wit…

Right but this only means you can decrypt data coming from websites using a starfish cert. It doesn't mean you can decrypt your bank traffic because you have this proxy installed which is what Graham is claiming.

Yes, it does mean others can decrypt your bank traffic.

Here's how this type of MITM attack works.

Situation: user is using laptop in public location with WiFi. Between WiFi device and net is a computer with MITM software.

Client laptop requests "https://www.bigbank.com". MITM box gets HTTPS request, sees it is for "bigbank.com", and generates a fake cert for that site. It then uses the Superfish root cert to sign the fake cert. MITM box acts as server for that connection and sees the user's traffic in the clear, unencrypted. The Lenovo client laptop sees a valid cert chain descending from the Superfish cert installed by Lenovo. The user sees a green bar and lock icon.

MITM box then opens an HTTPS connection to "https://www.bigbank.com", and acts as client for that connection. The two connections are connected together as a proxy, so that the user sees what looks like a valid HTTPS connection. The MITM box can log everything, including bank passwords.

There's even open source software for doing MITM attacks: https://code.google.com/p/subterfuge/

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#208
post #56

Earlier quoted context omitted.

They did admit the problem and linked page describing how to remove SuperFish. > We're sorry. We messed up. We're owning it. And we're making sure it never happens again. Fully uninstall Superfish: http://lnv.gy/182BW8g https://twitter.com/lenovoUS/status/568578319681257472

Only after various rounds of denials followed by backlash against them. Even their "removal" instruction initially failed to fully remove the root certificate. Every single step they made PR-wise was too slow and just reactionary to the backlash. Somebody up there should be fired and replaced.

Oh, OK. Was not aware about that.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#209
post #203

Earlier quoted context omitted.

NSAKEY ... Though I believe virtually all preloads were OEM actions, not Microsoft's directly.

NSAKEY don't count either.

I've never been fully convinced by arguments on either side of that discussion. Always struck me as suspicious though.

Hell of a name, you've got to admit.

Bruce Schneier's discussion at the time:

http://web.archive.org/web/20011005071623/http://www.counter...

One of his speculations:

it is actually an NSA key. If the NSA is going to use Microsoft products for classified traffic, they're going to install their own cryptography. They're not going to want to show it to anyone, not even Microsoft. They are going to want to sign their own modules. So the backup key could also be an NSA internal key, so that they could install strong cryptography on Microsoft products for their own internal use.

Though given alternative methods of bypassing any Microsoft security, not really necessary.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#210
post #62

I warned all my friends and colleagues who use Lenovos, and their answers were all the same. "Who'd be crazy enough to use the default install? First thing I did was (a fresh reinstall of Windows|install Linux)." (Edit: Obviously this is not representative of the general population, and I didn't mean to suggest it was. I was just noting that my efforts to warn people about the untrustworthiness of Lenovo were thwarte…

This is repeatedly recommended, but I think it's overlooking that not all manufacturer customization is entirely evil. You then to hunt down all the drivers for bits of the motherboard. Are you sure your power consumption settings etc are optimal after you've done this? Have you installed all the drivers "manually" via their inf files? (e.g. Nvidia drivers come with their own pile of bloatware)

But by tying in good and quite obviously bad customizations, you're attacking the entire value proposition of a vendor preload.

It's why I've, in general, never trusted them.

Post reply on HN