Earlier quoted context omitted.
Honestly, I think that's unlikely. This is far too sloppy to have been intentional. There are much better ways to implement a backdoor when you control the OS image. This is just incompetence, plain and simple. Superfish looks like the kind of crapware that pays OEMs to include it in their bundle. Lenovo took the cash and didn't bother to review the code. Superfish, for its part, probably doesn't have the best and br…
Cannot see how this could possibly be true. Having been privy to OS bundling for products, I can assure you there is lengthy contracts, and negotiations, about exactly what is happening. You do no simply walk up to Lenovo and have your "software" installed into the OS without a very detailed contract and pay structure. There also looks to be js injected into pages, which is serving up the ads, and a comment about Len…
Lenovo Caught Installing Adware on New Computers
81–90 of 435 posts
Re: Lenovo Caught Installing Adware on New Computers
#82I am guessing the Lenovo machines that are bought from the Microsoft Store are free of this, because of the Signature PC program, might be worth the extra cost if any and the trip there to get a crapware free machine.
Re: Lenovo Caught Installing Adware on New Computers
#83Was just about to purchase a lenovo... although I would have wiped it and installed linux immediately this has caused me to look elsewhere. when will companies learn this kind of behavior is toxic to their business?
Unfortunately a very small proportion of potential customers are going to hear or care about this... it's about as toxic to their business as stepping in some stinging nettles is toxic to me.
Re: Lenovo Caught Installing Adware on New Computers
#84Earlier quoted context omitted.
arguably? That's orders of magnitude worse
Well, I dunno. In one case Superfish can see all your data and store it on their servers, in the other case _anyone on the internet_ can spoof any site (as soon as someone extracts the key). Either way is pretty bad. But proxying all traffic from all Lenovo laptop owners through a third-party server without someone immediately noticing a problem is just not feasible, so I think we can assume that's not what they're d…
Re: Lenovo Caught Installing Adware on New Computers
#85Earlier quoted context omitted.
What is it that the firmware can achieve? Is the firmware capable hijacking data, communicating with the NIC and transmitting data? Or is it somehow injecting harmful code? I feel like I'm missing something here.
Ripped from yesterday's headlines ... ... rewrote the hard-drive firmware of infected computers—a never-before-seen engineering marvel that worked on 12 drive categories from manufacturers including Western Digital, Maxtor, Samsung, IBM, Micron, Toshiba, and Seagate. The malicious firmware created a secret storage vault that survived military-grade disk wiping and reformatting, making sensitive data stolen from victi…
Re: Lenovo Caught Installing Adware on New Computers
#86First thing I also do on a new PC is reinstall the OS from scratch and get rid of all the preinstalled shit.
Your strategy works only if you have a clean copy of the OS or you buy one (since the thread is about Lenovo I assume you are talking about Windows). Typically, a new PC doesn't come anymore with a copy of the OS, but with a hidden recovery partition that will basically let you do a factory reset (meaning all the crap will show up again).
And of course Windows 10 will be a free download.
Re: Lenovo Caught Installing Adware on New Computers
#87This is much worse than just installing adware. They install a web proxy which MITMs all web connections, including HTTPS by means of a pre-installed trusted root certificate. The root certificate is the same across all installs, and the private key is present on the machine (necessarily, to operate the proxy): https://twitter.com/fugueish/status/568258997578371072 Someone will extract the private key in the next few…
Is there reason to believe that the same key is used on all machines?
Re: Lenovo Caught Installing Adware on New Computers
#88Earlier quoted context omitted.
Well, I dunno. In one case Superfish can see all your data and store it on their servers, in the other case _anyone on the internet_ can spoof any site (as soon as someone extracts the key). Either way is pretty bad. But proxying all traffic from all Lenovo laptop owners through a third-party server without someone immediately noticing a problem is just not feasible, so I think we can assume that's not what they're d…
Are you sure? Android Chrome proxies all non-HTTPS traffic through a third-party server, by default. So it isn't like the traffic volume is impossible.
Re: Lenovo Caught Installing Adware on New Computers
#89Lenovo was the last respected PC laptop brand. Is there anyone I can trust to sell me a well-made laptop anymore besides Apple?
Re: Lenovo Caught Installing Adware on New Computers
#90Lenovo doesn't stand out as much as they used to. Dell/HP/Apple make pretty great business laptops these days. If everything else is equal and I know the competitor (for example) won't install adware, then why would I ever buy Lenovo again?