Live data from Hacker News

Lenovo Caught Installing Adware on New Computers

thenextweb.com

111–120 of 435 posts

Re: Lenovo Caught Installing Adware on New Computers

#112
post #5

This is much worse than just installing adware. They install a web proxy which MITMs all web connections, including HTTPS by means of a pre-installed trusted root certificate. The root certificate is the same across all installs, and the private key is present on the machine (necessarily, to operate the proxy): https://twitter.com/fugueish/status/568258997578371072 Someone will extract the private key in the next few…

I'm confused; if Firefox doesn't use the system certificates, shouldn't Firefox users have been seeing visibly broken HTTPS from day one?

Re: Lenovo Caught Installing Adware on New Computers

#113
post #89

Lenovo was the last respected PC laptop brand. Is there anyone I can trust to sell me a well-made laptop anymore besides Apple?

Asus is about it.

I own two Asus products - Nexus 7 2012 and a K55VM series laptop. Both had problems with charging and used to get hot pretty soon.

Re: Lenovo Caught Installing Adware on New Computers

#115
post #94
post #80

Earlier quoted context omitted.

Oh I'm sure they had lots of meetings about the contracts and pay structure, and they may have done testing to make sure it didn't break things, but apparently no one did a security review. Sadly, this doesn't surprise me that much. If they did know about the problem, they could have fixed it. If the app simply generated a new key as part of first-time use, then it would just be run-of-the-mill crapware rather than a…

but apparently no one did a security review It doesn't take a "security review" to spot a gaping security and privacy violation like this. Any engineer with even the slightest clue of how a browser and "the internet" works would have called this out during the first "How does this product work?"-presentation. Let's not pretend Lenovo is staffed with monkeys.

“Never ascribe to malice that which can adequately be explained by incompetence.”

Remember stuff like this:

http://www.cryptofails.com/post/70059600123/saltstack-rsa-e-...

(Which, possibly unfairly, is one reason I'm leaning more towards ansible than saltstack to this day -- I mean, if stuff like that got through... what else, in more complex areas of the system?)

Re: Lenovo Caught Installing Adware on New Computers

#116
post #94
post #80

Earlier quoted context omitted.

Oh I'm sure they had lots of meetings about the contracts and pay structure, and they may have done testing to make sure it didn't break things, but apparently no one did a security review. Sadly, this doesn't surprise me that much. If they did know about the problem, they could have fixed it. If the app simply generated a new key as part of first-time use, then it would just be run-of-the-mill crapware rather than a…

but apparently no one did a security review It doesn't take a "security review" to spot a gaping security and privacy violation like this. Any engineer with even the slightest clue of how a browser and "the internet" works would have called this out during the first "How does this product work?"-presentation. Let's not pretend Lenovo is staffed with monkeys.

You're so optimistic it hurts

"Any engineer" means something in HN, but we're not talking about "people who read HN" levels of engineer here, don't be mistaken.

Some people that have had no or limited experience with software are assigned to software projects, and that's the issue with companies like Lenovo.

Re: Lenovo Caught Installing Adware on New Computers

#117

Was just about to purchase a lenovo... although I would have wiped it and installed linux immediately this has caused me to look elsewhere. when will companies learn this kind of behavior is toxic to their business?

Unfortunately a very small proportion of potential customers are going to hear or care about this... it's about as toxic to their business as stepping in some stinging nettles is toxic to me.

Unfortunately they have no competition in terms of a quality laptop to run Linux on. None of the competition offers similar features as my current x230 or the x250 I'm probably going to pick up later this year. If you could recommend a replacement that has a good keyboard, trackpoint, 12+ hours of real battery life, i7, etc. I'd be happy to hear about it.

Re: Lenovo Caught Installing Adware on New Computers

#118
post #89

Earlier quoted context omitted.

Asus is about it.

I thought so too, but my recent experience with a Zenbook has changed my view. WiFi drivers were so bad it took half a year after my purchase before the connection became stable (not dropping every 15 minutes requiring a reboot). Touchpad drivers were also a mess with awful kinetic scrolling. And just couple of weeks ago it stopped booting Windows altogehter (something related to ACPI I guess, Linux works if I don't…

Despite the initial problems, I like my Zenbook.

The WiFi drivers are made by Intel, but yes, they were terrible (blue screen). I had to downgrade back to the drivers that came with Windows for while but the latest versions seem to be fine. I'm using some stock touchpad drivers that don't seem to have any kinetic scrolling.

But I'm the person who brought this to the attention of Hacker News: https://news.ycombinator.com/item?id=8546702

Basically after installing just about everything the laptop comes with, it seems to be running great. :)

Re: Lenovo Caught Installing Adware on New Computers

#119
post #51
post #5

This is much worse than just installing adware. They install a web proxy which MITMs all web connections, including HTTPS by means of a pre-installed trusted root certificate. The root certificate is the same across all installs, and the private key is present on the machine (necessarily, to operate the proxy): https://twitter.com/fugueish/status/568258997578371072 Someone will extract the private key in the next few…

I'm curious what legal stance Lenovo customers have here - their secure HTTPS connections are being MITMed intentionally - surely that's hacking, or some national security violation?

> their secure HTTPS connections are being MITMed intentionally

of course they are - Lenovo customers have signed the agreement that this is ok when they started the machine the first time

Re: Lenovo Caught Installing Adware on New Computers

#120

Lenovo going down the drain. All they had to do was continue the Thinkpad legacy left by IBM. It's honestly breathtaking how badly they've fucked up. After the touch-based function keys, ruining the trackpoint buttons and now this. It's unbelievable.

They brought the trackpoint buttons back on the latest line and you can switch the F-keys back to being the defaults via a bios setting. Just in case you were curious.
Post reply on HN