Live data from Hacker News

Lenovo CTO: We’re Working to Wipe Superfish App Off of PCs

blogs.wsj.com

21–30 of 54 posts

Re: Lenovo CTO: We’re Working to Wipe Superfish App Off of PCs

#21
post #5

I wouldn't trust this company anymore. Bye Lenovo.

Nearly every laptop is preloaded with crapware. Lenovo might have (briefly even) picked one of worst examples of it but I'm sure there are (or will be) examples of this from other manufacturers that has yet to be discovered. It might now be the case going forward that Lenovo will be a better choice. They've been burned.

There's crapware, and then there's spyware/adware.

The shovelware that most vendors ship on their boxes is offensive, yes. It's annoying. It steals a little of my life each time I buy a new machine, because I have to take time to re-image the system or clean off the crap (my current HP Envy was particularly egregious in this waste of my time, in that the restore image didn't work, so I had to wait ten days to get a restore DVD from them, and had to pay them $15 for the privilege of being able to restore my system). But, none of this is comparable to installing spyware on your customers systems.

They keep making claims that it isn't spyware, but in a previous HN thread, someone was trivially able to find the tracking and re-targeting codes in the injected code. It is the definition of spyware, and even worse, it is broken in such a way that it enabled MITM attacks.

"It might now be the case going forward that Lenovo will be a better choice. They've been burned."

Have you read their statements about it? Every single one of them denies any wrongdoing. They believe it's just a "customers don't like this software" issue. They don't believe it is a "We have likely committed crimes against our customers", which is what it actually is, at least in jurisdictions that take citizen privacy at all seriously. (In the US the TOS click through probably protects them, because the US doesn't give a shit about privacy, but in some other countries it probably wouldn't.)

Re: Lenovo CTO: We’re Working to Wipe Superfish App Off of PCs

#22
If you run a website and you'd like to help spread awareness to victims of this heinous crime, a technique such as this might work:

https://paste.ee/p/y1RvZ

These are the URLs on the malware peddler's server I examined to get an idea for how to detect whether their malicious payload injection has taken place:

https://www.best-deals-products.com/ws/sf_code.jsp

https://www.best-deals-products.com/ws/sf_preloader.jsp

https://www.best-deals-products.com/ws/sf_main.jsp?dlsource=...

Re: Lenovo CTO: We’re Working to Wipe Superfish App Off of PCs

#23

Earlier quoted context omitted.

This is cluebat level of ignorance. I want to apply the "don't ascribe to malice what can adequately be explained by ignorance" maxim, but I'm having trouble with the "adequately" here. Either they managed to live under a rock and completely ignore everything related to the Snowden revelations, or they're willfully dismissing it. Such a pity, I was looking forward to getting an X1...

The price of "don't ascribe to malice" is that it's trivial to exploit. The most incompetent PR department in the world can have a strict adherent on a leash and barking to their tune inside of 5 minutes. Courts of law have a good reason to hold high standards of evidence. For everyone else it's just an excuse for laziness. Not that I'm any better, I just don't insist on rationalizing it :-)

I'm now old and cynical enough to understand/believe that the world is run with laziness as the prime heuristic (with secondary heurisitc being "don't die/maintain current level of comfort").

I agree that it's trivial to exploit, but I choose to believe that, in the general case, people/entities are lazier than they are evil. That said, laziness can be in the form of "not taking into account the externalities", which can be indistinguishable from actual malice (which I define as knowingly and/or willfully causing harm).

I still think Lenovo's behaviour in this case is that form of laziness, though my comment above means I'm on the fence.

Re: Lenovo CTO: We’re Working to Wipe Superfish App Off of PCs

#24
post #13

"We’re not trying to get into an argument with the security guys. They’re dealing with theoretical concerns." - Peter Hortensius I'd say that someone having cracked out the password for the private key is a bit more than a 'theoretical' concern. This might be the most tone-deaf handling of a potential PR disaster so far this year.

> This might be the most tone-deaf handling of a potential PR disaster so far this year. It's appealing to a common and sucessful strategy of dismissing the concerns of experts as the irrelevant waffling of a bunch of eggheads disconnected from reality. Lenovo are hoping their user base will pop "security researchers" in the same bucket as beachfront property owning SUV drivers place "climate scientists".

What about private-jet-plane-flying-climate-scientists and (especially) worriers?

Re: Lenovo CTO: We’re Working to Wipe Superfish App Off of PCs

#25
Lenovo should just offer the unbiased, truthful and transparent choice between a clean image (with device drivers) and their usual crapware image. They can then easily gather metrics on what image is selected when customers order products. Just give customers a choice!

Re: Lenovo CTO: We’re Working to Wipe Superfish App Off of PCs

#26
post #6

> Hortensius: In general, we get pretty good feedback from users on what software we pre-install on computers. LOL. Yes sir! The internet is filled with people happy about bloatware... I seriously wonder how much money they make off these bloatware providers to risk pissing off customers and devalue their brand. It can't be that much can it?

The weird part is, I've bought three Lenovos of my own and never had a problem with their preinstalled software. Some of it, like the ThiknVantage suite, can even be useful. Maybe it's because I buy from the Thinkpad line? Do they install less crap on Thinkpads than on IdeaPads or other laptops?

Yeah. I have a ThinkPad T530 and a Yoga Pro 3 and while it's not a fair comparison (mobile workstation vs. strange laptop/hybrid...thing) the software on the ThinkPad feels more sparse and out of the way while the stuff on the Yoga is pretty terrible and invasive.

Re: Lenovo CTO: We’re Working to Wipe Superfish App Off of PCs

#27

"We’re not trying to get into an argument with the security guys. They’re dealing with theoretical concerns." - Peter Hortensius I'd say that someone having cracked out the password for the private key is a bit more than a 'theoretical' concern. This might be the most tone-deaf handling of a potential PR disaster so far this year.

> This might be the most tone-deaf handling of a potential PR disaster so far this year.

I think you're assuming that the broader public shares the indignation of HN about this. On mainstream news sites, it's down under the 'technology' heading. It sounds like Lenovo is scrambling a fix that will remove the certificate. If that's out in the next day or two and they have a way to get most affected users to apply it, probably hardly anyone will get clearly 'hacked'. They'll keep playing the 'honest mistake' card, and it will mostly blow over.

Re: Lenovo CTO: We’re Working to Wipe Superfish App Off of PCs

#28
post #19

Hortensius says Lenovo failed in due diligence. How, exactly? The two reasons people are upset about Superfish are that it breaks web security and injects ads into pages. Hortensius doesn't believe the former, and the latter is the entire purpose of the software. The only failure he could mean, taking him at his word, is in not anticipating the backlash, because as he describes it Superfish works as intended.

From a corporate perspective, Hortensius approved the bundling of adware (so he's ok with it) from what he thought was a reputable third-party software company. He was wrong!

http://marcrogers.org/2015/02/19/will-the-madness-never-end-...

Re: Lenovo CTO: We’re Working to Wipe Superfish App Off of PCs

#29
post #6

> Hortensius: In general, we get pretty good feedback from users on what software we pre-install on computers. LOL. Yes sir! The internet is filled with people happy about bloatware... I seriously wonder how much money they make off these bloatware providers to risk pissing off customers and devalue their brand. It can't be that much can it?

The last time I bought a Thinkpad (which was admittedly ten years ago) it didn't have anything I'd describe as bloatware. The quality of some of it was lacking, but it was all useful.

Re: Lenovo CTO: We’re Working to Wipe Superfish App Off of PCs

#30
Some articles posted with a picture of thinkpad which is non-affected products for this issue.

>>Lenovo Y50, Z40, Z50, G50 and Yoga 2 Pro models.

Above is announced from some sources and

>>Lenovo-branded devices sold between September 2014 and January 2015 through consumer online and retail stores, like Best Buy and Amazon.com, are likely affected by the Superfish adware

Has anyone got any additional info?

Post reply on HN