Live data from Hacker News

Lenovo Statement on Superfish

news.lenovo.com

241–250 of 312 posts

Re: Lenovo Statement on Superfish

#241

Earlier quoted context omitted.

The number one source of viruses on a Mac is anti-virus software, don't install it. No system is impervious, there are levels of risk. Apparently the highest possible risk is running a stock Lenovo.

I don't run AV software on my Mac because the threat and possible consequences are sufficiently limited. But I've never heard about AV software itself being a vector. Where can I find out more?

I imagine that comment referred to fake antivirus software from webpage ads or something that users are tricked into installing. Something like ClamAV would be fine.

Re: Lenovo Statement on Superfish

#242
post #4

> We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns. I try to be measured around here, as hard as I can. I can't formulate a polite way to respond to this claim. Lenovo, you are full of shit, and maliciously so. There is no excuse, nor forgiveness, for what you've done here.

No evidence of security concerns, you say, Lenovo!? Well then your entire C-suite will put their money where their mouth is by browsing with these "uncompromised" machines for the forseeable future, right? Banking, signing in to their hospital's website, logging in to corporate sites...

Wait, your IT department just frantically rolled out clean disk images to the whole org? That's a funny coincidence...

Re: Lenovo Statement on Superfish

#243

Earlier quoted context omitted.

Indeed. I have been buying IBM and then Lenovo Thinkpads for ages. I hate the thought that my next machine will be another brand. Lenovo: One customer lost. More to be lost.

Why stop buying Thinkpads? Lenovo have acknowledged the issue and are now trying to resolve it. Everybody makes mistakes but how they fix those problems tells you a lot about the culture of the company. Lenovo also made a terrible mistake in removing the physical click buttons, but is now reintroducing them across their entire laptop range for 2015. What I see is a company willing to listen and admit their mistakes.…

That is not a mistake. That is a deliberate, well planned action done by management.

If they had asked someone with a clue before, that wouldn't have happened.

Re: Lenovo Statement on Superfish

#244

Earlier quoted context omitted.

> Lenovo: One customer lost. More to be lost. Never purchased a Lenovo but I was bent on using one for my next machine. No longer. Their lies about it "not being a risk" have put the affected customers at immense risk.

Doesn't matter what machine you're using if your ISP e.g. Comcast is injecting ads into the web pages you visit!

Luckily this is not [yet] an issue where I live. I am an extremely deliberate consumer, though. I have evaluated competition and terminated contracts for far less than this.

Just because others are doing it, does not make it right.

Re: Lenovo Statement on Superfish

#245

Earlier quoted context omitted.

Clearly Lenovo are stupid for bundling third-party ad-injection software, but who knows what Apple are doing behind closed doors? e.g. CarrierIQ in the baseband... etc.

Just to be clear, this is Apple, the company famous for putting user experience ahead of everything else (and often criticized by developers for putting user experience ahead of developer experience). Apple, the company that routinely tops customer satisfaction surveys. Apple, the company that has gone on the record time and time again about how user-focused they are. There are plenty of valid things to criticize App…

This Lenovo press release is evidence neither for nor against Apple's malfeasance. But I think we can all agree that if Apple does bundle malware, that malware's user experience will be thoughtful, smooth, and superbly curated. /s

Re: Lenovo Statement on Superfish

#246
post #129

Earlier quoted context omitted.

Indeed. I have been buying IBM and then Lenovo Thinkpads for ages. I hate the thought that my next machine will be another brand. Lenovo: One customer lost. More to be lost.

If you re-installed your OS and didn't use the factory image (which always includes other bloatware), then you were not affected. Or if you installed another OS (Linux, BSD, etc) then you were not affected. I love my thinkpad... but I've always paved over the factory image the moment I got my new laptop. This is egregious beyond a doubt, but it does not affect me so I'm not worried about buying more of their laptops.

It doesn't matter, if _I_ was affected or not. It matters that thousands of others _are_ affected and that I fucking care what my friends and family run.

Oh and that I run a website over https matters too. I want that all users have the same expectation what that means.

Re: Lenovo Statement on Superfish

#247

Earlier quoted context omitted.

Indeed. I have been buying IBM and then Lenovo Thinkpads for ages. I hate the thought that my next machine will be another brand. Lenovo: One customer lost. More to be lost.

Or simply wipe the HDD and reinstall OS.

_I_ might be able to do so (well, frankly I am) but the point is, others are not.

Re: Lenovo Statement on Superfish

#248
post #129

Earlier quoted context omitted.

Indeed. I have been buying IBM and then Lenovo Thinkpads for ages. I hate the thought that my next machine will be another brand. Lenovo: One customer lost. More to be lost.

If you re-installed your OS and didn't use the factory image (which always includes other bloatware), then you were not affected. Or if you installed another OS (Linux, BSD, etc) then you were not affected. I love my thinkpad... but I've always paved over the factory image the moment I got my new laptop. This is egregious beyond a doubt, but it does not affect me so I'm not worried about buying more of their laptops.

I've always been curious about how this work. If I buy a Win machine and want to keep Win (say to dual-boot), how do I do this? Buy a second OS disk? Torrent one and use my key?

I get it if I'm wiping out and putting on Linux or something, but that always seems like I'm wasting something I've already bought.

Re: Lenovo Statement on Superfish

#249

Earlier quoted context omitted.

Indeed. I have been buying IBM and then Lenovo Thinkpads for ages. I hate the thought that my next machine will be another brand. Lenovo: One customer lost. More to be lost.

Lenovo is a hardware vendor. I suspect most of the HN crowd reinstalls something on their machines. The non-HN crowd won't even know about all of this (see the public response to NSA spying on American citizens, almost zero).

All HN-crowd have friends, family and other folks who "don't know about that". And some of them bought those devices.

But what the fucking fuck have people not understood about this issue?

Someone might run open, free access points, sucking people in to connect and then they fucking MITM everything - inclusive that money transfer from your relative to you. How about that? Yes, you might be affected by this huge fuck up from Lenovo.

Re: Lenovo Statement on Superfish

#250
post #129

Earlier quoted context omitted.

Indeed. I have been buying IBM and then Lenovo Thinkpads for ages. I hate the thought that my next machine will be another brand. Lenovo: One customer lost. More to be lost.

If you re-installed your OS and didn't use the factory image (which always includes other bloatware), then you were not affected. Or if you installed another OS (Linux, BSD, etc) then you were not affected. I love my thinkpad... but I've always paved over the factory image the moment I got my new laptop. This is egregious beyond a doubt, but it does not affect me so I'm not worried about buying more of their laptops.

It might affect you. Your friends/families traffic on these machines are suspectible to a MITM. Rogue access points, etc etc are a problem these days.

So, that communication your girlfriend might send you over https is not private any longer.

Go figure.

Post reply on HN