Live data from Hacker News

Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

wired.com

211–220 of 225 posts

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#211
post #88

I warned all my friends and colleagues who use Lenovos, and their answers were all the same. "Who'd be crazy enough to use the default install? First thing I did was (a fresh reinstall of Windows|install Linux)." (Edit: Obviously this is not representative of the general population, and I didn't mean to suggest it was. I was just noting that my efforts to warn people about the untrustworthiness of Lenovo were thwarte…

I'm on my 4th Thinkpad. I always do a fresh install of Linux, would never trust the pre-installed crap. But now that I know that Lenovo is a piece of shit company with zero integrity, I don't even want to trust their hardware.

I'm at the level of hardware trust issues myself.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#212
post #72

Earlier quoted context omitted.

Microsoft has done some shady things, but at no time in Microsoft's history would they have installed this.

You should look into some of the stuff MS did in the glory years, such as deliberately breaking rival software from Lotus, Borland, and Apple.

I'm not sure how that's relevant to this. It's bad, as I allowed in my statement, but I'm not seeing other parallels.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#213
post #135

Earlier quoted context omitted.

At least "Lenovo US" is owning up to it. https://twitter.com/lenovoUS/status/568578319681257472 Not sure how they're connected to the "Lenovo" that issued that statement.

Seems to be a lot of self-righteous moral crusaders on Twitter, and some on HN too, who won't be satisfied until they see Lenovo employees hanging from lamp posts...

Violent murder is not an appropriate response to this, but certainly somebody (probably multiple people in the upper echelons of Lenovo) should be fired. The damage to Lenovo's reputation from this is enormous.

Even if 'average people' have no idea what a certificate is or why it's important, those who do have an outsized influence on PC purchasing, and are likely to remember this for years.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#214

Earlier quoted context omitted.

Right but this only means you can decrypt data coming from websites using a starfish cert. It doesn't mean you can decrypt your bank traffic because you have this proxy installed which is what Graham is claiming.

Yes, it does mean others can decrypt your bank traffic. Here's how this type of MITM attack works. Situation: user is using laptop in public location with WiFi. Between WiFi device and net is a computer with MITM software. Client laptop requests " https://www.bigbank.com" . MITM box gets HTTPS request, sees it is for "bigbank.com", and generates a fake cert for that site. It then uses the Superfish root cert to sign…

If you have a computer between the user and net, then yes all bets are off because you can generate certs the browser will trust.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#215

Earlier quoted context omitted.

Defender is my current Windows anti-malware software of choice. Basically, because they don't feel they have to shill so hard as the other AV companies, and this makes their user experience suck the least.

Yes, and: it's preinstalled on Windows 8, it costs nothing, and it's made by the very same company whose product it tries to protect, so incentives and motivation are clear (an exception to "if you're not paying you're the product"). It's quite a convincing product, quickly becoming an integral part of the OS. And rightfully so.

> It's quite a convincing product, quickly becoming an integral part of the OS. And rightfully so.

Not really. Microsoft, itself, actually suggests that you use a third-party antimalware product.

It scores pretty low on AV-Test.org[1] too, but it's better than nothing.

[1]: http://www.av-test.org/en/antivirus/home-windows/windows-8/

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#216
post #178

Earlier quoted context omitted.

You accused him (and me, and others who voted up this story) of being either a "brigading Microsoft fan" or a "paid shill". Sorry, but that's just false as far as I can tell. He cited those things as the reason for his other comment's moderation. Please quote the text from which you draw your conclusions of attribution.

jhou2: the amount of positive press that MS has been garnering recently on HN is impressive engendered: Don't think it is purely happenstance. There is absolutely and unequivocally either brigading Microsoft fans, or paid shills, hitting HN hard. My interpretation might be wrong, but I take jhou2's "positive press" to mean stories such as this one appearing on the front page. I interpret 'engendered' as saying that t…

My interpretation might be wrong

Thanks for that moment of intellectual honesty. The following two paragraphs strike me to be as much of a stretch as his theory.

I am more likely to vote up a good deed done by Microsoft because I find it to be more noteworthy than a good deed done by others.

Credit where credit is due is commendable.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#217

Earlier quoted context omitted.

Yes, but MiTM isn't the same as sniffing packets over a wifi in a cafe, which what Graham claimed.

If you can read (sniff) WiFi in a cafe, you can write (MiTM), so the difference isn't really important, is it?

Usually sniffing refers to capturing packets. But yes if you can read and write then you can definitely decrypt the traffic since you can provide the user with a trusted cert.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#218

Earlier quoted context omitted.

Yes, it does mean others can decrypt your bank traffic. Here's how this type of MITM attack works. Situation: user is using laptop in public location with WiFi. Between WiFi device and net is a computer with MITM software. Client laptop requests " https://www.bigbank.com" . MITM box gets HTTPS request, sees it is for "bigbank.com", and generates a fake cert for that site. It then uses the Superfish root cert to sign…

If you have a computer between the user and net, then yes all bets are off because you can generate certs the browser will trust.

Only if the root cert store of the user's machine has been tampered with. If you have a valid cert store, you can detect MITM attacks on HTTPS connections.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#219

Earlier quoted context omitted.

If you have a computer between the user and net, then yes all bets are off because you can generate certs the browser will trust.

Only if the root cert store of the user's machine has been tampered with. If you have a valid cert store, you can detect MITM attacks on HTTPS connections.

yep. I was referring to superfish's case.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#220
post #39

Earlier quoted context omitted.

The key word is significant . They're not claiming they didn't preload this software for money, they're just saying it wasn't for very much money. Such a small amount of money that they have no problem ending the relationship now that it's causing them problems. My wild guess would be they got in the ballpark of $0.25 an install.

I'm not even that miffed about being a product and not the customer; I am incredibly miffed that I'm apparently one of the products in the discount bin.

I am miffed, actually. I own a Lenovo laptop and it was not cheap. Fortunately it dates back to well before this thing and has a clean OS install anyway, but.

They sell laptops. It's not a free service, I am the customer not the product. Did Lenovo have a pressing financial need for these extra pennies on the side? Really? How is that benefit vs risk calculation looking now?

Post reply on HN