Live data from Hacker News

Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

wired.com

131–140 of 225 posts

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#131
Lenovo's response is not astonishingly in the least, its the expected behavior. They made a business decision to include adware in order to raise some extra revenue and then got caught. The default response is to underplay the importance of it, sweeping it under the rug and hope no legal action will happen.

A few months ago there was a HN story about a car manufacturer who had made the decision to use cheaper parts for the ignition. They had the critical internal reports from engineers, and when the deaths started to pile up they did the same thing as lenovo. Act clueless, downplay the issue, make a fix, and silently move on. So long it just customer outrage, it is perfectly fine to do borderline illegal things in order to raise some revenue.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#132

It tickles me that Superfish is a DFJ-funded [1] start-up based out of Palo Alto. Reporters are focussing on Lenovo's Chinese lineage. Yet this bubbled up out of our backyard, from our own lack of diligence (or scruples). [1] Edit: Draper Fisher Jurvetson, the $4 billion Menlo Park VC firm that backed Baidu, Hotmail, Tesla, SpaceX and Twitter.

[deleted]

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#133

Earlier quoted context omitted.

Does everything have to be a conspiracy? So either Microsoft is building some good and interesting stuff, or there's some conspiracy to target HN that would get them...what, exactly? +Karma here?

Does my statement somehow make everything a conspiracy? Boy, we on HN are supremely good at knocking down those strawmen. "or there's some conspiracy to target HN that would get them...what, exactly? +Karma here?" Is this supposed to be intentionally naive? Microsoft is a technology company that heavily relies upon buy in and advocacy. Is this really difficult to understand? Every single comment to my post has either…

No, not intentionally naive, but perhaps intentionally not cynical. I'd like to believe that a technology company, such as Microsoft, relies on a bit more than buy-in and advocacy. Perhaps the soundness of a product, for example.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#134

Earlier quoted context omitted.

Does everything have to be a conspiracy? So either Microsoft is building some good and interesting stuff, or there's some conspiracy to target HN that would get them...what, exactly? +Karma here?

Not just karma, too many lazy engineers choose their stack almost solely on a quick scan on HN to see what's cool. You can date many startups by first looking at their stack, and then checking when that stack was cool here.

Not only here but in general "coolness" is one of the main factors for choosing tech in startups.

2008 - So did you rewrite your PHP apps in Ruby?

2012 - So did you rewrite your Ruby apps in Node?

2015 - So did you rewrite your Node apps in Go?

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#135
post #13

Microsoft is currently doing Lenovo's work for them: https://twitter.com/FiloSottile/status/568800260111388672 The latest version of Windows Defender is actively removing the Superfish software and the cert. The text of the definition is here: http://pastebin.com/raw.php?i=us7iXvkn

At least "Lenovo US" is owning up to it. https://twitter.com/lenovoUS/status/568578319681257472 Not sure how they're connected to the "Lenovo" that issued that statement.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#137

Earlier quoted context omitted.

Does everything have to be a conspiracy? So either Microsoft is building some good and interesting stuff, or there's some conspiracy to target HN that would get them...what, exactly? +Karma here?

Does my statement somehow make everything a conspiracy? Boy, we on HN are supremely good at knocking down those strawmen. "or there's some conspiracy to target HN that would get them...what, exactly? +Karma here?" Is this supposed to be intentionally naive? Microsoft is a technology company that heavily relies upon buy in and advocacy. Is this really difficult to understand? Every single comment to my post has either…

Without discounting the possibility that there may be some astroturfing, I think it's far more likely that you've run afoul of community expectations.

The HN guidelines specifically suggest you resist commenting on downvotes, and people take that seriously here. Editing your comment to add meta-commentary on votes will generally just get you more downvotes.

Additionally, your comments are fairly polarizing. You make statements about how something is obvious, but then provide nothing besides anecdotal evidence. If it's that obvious, real evidence should be easy to show, otherwise it's possibly not as clear as you think. You could possibly have avoided this problem by framing it as a question and leaving an opening for someone to provide a better answer. This also invites people who disagree, or have a different interpretation to engage in a useful way, rather than starting off in an antagonistic way. For example, stating something "absolutely and unequivocally" without evidence won't generally be seen useful to the discussion here.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#138
post #116

Earlier quoted context omitted.

A different way to frame the comment might be something like: "we were willing to sell out your privacy and security for a mere pittance, 'cause we're cheap whores".

I assume they didn't intend to compromise security. I think it's more accurate to say that they stiffed their users with adware that nobody wants in exchange for a little bit of money, and that were so indifferent to security and privacy while doing it that either didn't notice or didn't care that it was a fundamentally bad idea.

In my opinion that is worse. Most any clueful technocrat can tell you that injecting traffic into HTTPS sessions is a MITM attack. I am willing to bet that fact most certainly did make it to an executive level (certainly at the fishy company) and a choice was made to not care about that problem.

The road to poor security is paved with indifference.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#139
post #14

I warned all my friends and colleagues who use Lenovos, and their answers were all the same. "Who'd be crazy enough to use the default install? First thing I did was (a fresh reinstall of Windows|install Linux)." (Edit: Obviously this is not representative of the general population, and I didn't mean to suggest it was. I was just noting that my efforts to warn people about the untrustworthiness of Lenovo were thwarte…

You live in a bubble. There are plenty of people who use Lenovo products that are not tech people. By saying this, even though you don't intend to, you are minimizing the effect of this and being an apologist for lenovo.

I don't like the attitude that if there's a problem, you aren't allowed to say anything along the lines of "here's something that makes it less of a problem than it might be".

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#140

I warned all my friends and colleagues who use Lenovos, and their answers were all the same. "Who'd be crazy enough to use the default install? First thing I did was (a fresh reinstall of Windows|install Linux)." (Edit: Obviously this is not representative of the general population, and I didn't mean to suggest it was. I was just noting that my efforts to warn people about the untrustworthiness of Lenovo were thwarte…

On that note, Microsoft seem to have taken down the windows digital downloads, OEM CD keys don't work. How would you do a fresh install now?

I had trouble finding Windows 8.1 iso files, but Windows 8.0 isos were easy to find, and upgrading was simple.
Post reply on HN