Live data from Hacker News

Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

wired.com

81–90 of 225 posts

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#81
post #70

Earlier quoted context omitted.

Don't think it is purely happenstance. There is absolutely and unequivocally either brigading Microsoft fans, or paid shills, hitting HN hard. There was a garbage post on the front page yesterday and I left a completely benign post that didn't go with the pro-Microsoft/anti-Google narrative -- saw -11 within less than 60 seconds.

shrug . I thought someone needed to do machine learning as a service, especially that can be accessed from Python, so I upvoted an article on Azure. I think presentation should be separate from data, so I upvoted a comment on posh. I'm a OS X / Linux person (my name's probably in your distro somewhere) and sometimes Microsoft does good stuff.

And, strangely, I didn't say otherwise. I'm typing this message on Windows. My main development IDE is Visual Studio. My primary RDBMS platform is SQL Server, deploy of course on Windows.

Yeah, the strawman that Microsoft can do no right is pretty easy to knock down, but has absolutely nothing to do with the context of this.

Again, a post on the second page (a ridiculous, extremely low quality post that had to be flagged off the front page) saw my benign comment get -11 within 60 seconds. I've never seen that before, much less for a completely moderate comment. I've seen this extremely pro-Microsoft moderation hit other threads hard, and it seems pretty obvious that it isn't by accident.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#82
post #13

Microsoft is currently doing Lenovo's work for them: https://twitter.com/FiloSottile/status/568800260111388672 The latest version of Windows Defender is actively removing the Superfish software and the cert. The text of the definition is here: http://pastebin.com/raw.php?i=us7iXvkn

15 years ago this would have led to rioting on slashdot and Usenet. How dare Microsoft remove someone else's software? I'm generally in favor of MS doing this specific thing, but there is potential for abuse here.

This is only is if Windows Defender is operational - in which case the user definitely wants the malware to be disabled/removed. It's akin to having a SPAM defender - in which you grant administrative rights to the owner of the Anti-SPAM tool to redirect spam to the bit-bucket.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#83

I warned all my friends and colleagues who use Lenovos, and their answers were all the same. "Who'd be crazy enough to use the default install? First thing I did was (a fresh reinstall of Windows|install Linux)." (Edit: Obviously this is not representative of the general population, and I didn't mean to suggest it was. I was just noting that my efforts to warn people about the untrustworthiness of Lenovo were thwarte…

I use a default install and I'm a techie. I just remove the bloatware first.

The last Lenovo laptop I got came with Norton. I uninstalled that completely. Then I went to download Chrome which Norton decided to protect me from. Uninstall means different things, and they never uninstall completely/cleanly. In this Superfish example they would have left the dodgy certificates behind. The only way you know you have a good install is to do a clean install, rather than attempt surgery on the crap that got shipped.

Fortunately Lenovo do have a system updater that does a fantastic job on driver downloads etc.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#84
post #26

Kudos to MS, srsly. lol the amount of positive press that MS has been garnering recently on HN is impressive.

Don't think it is purely happenstance. There is absolutely and unequivocally either brigading Microsoft fans, or paid shills, hitting HN hard. There was a garbage post on the front page yesterday and I left a completely benign post that didn't go with the pro-Microsoft/anti-Google narrative -- saw -11 within less than 60 seconds.

[deleted]

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#85
post #33

Earlier quoted context omitted.

Yes, it was only installed on their consumer oriented machines. Their T model Thinkpad don't have it installed. Now the question is of course what else are they installing and what other yet undiscovered issues we'll find. It sounds like FUD but so far based on their response, they seem either incompetent (stupid) or malicious. And I don't exactly like either...

I never quite got this distinction between consumer and non consumer machines, when you can buy high end ThinkPads (but not the blocky T models) at a retailer, and are just as nice as big old blocky good old ThinkPads. I'm really interested if a high end (but "consumer") ThinkPad like http://www.microsoftstore.com/store/msusa/en_US/pdp/Lenovo-T... that you can buy at a retail store (in this case, a special MSFT Store…

Consumers are often willing to buy poor, unreliable equipment to save a couple hundred dollars, but most businesses are not willing to do that.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#86
How on earth can Lenovo/Superfish state:

"But Superfish tells us it stands by Lenovo’s assessment. “Superfish is completely transparent in what our software does and at no time were consumers vulnerable—we stand by this today.” a company spokeswoman said. “Lenovo will be releasing a statement later today with all of the specifics that clarify that there has been no wrong doing on our end.”

Now that an official CERT announcement has been released:

https://www.us-cert.gov/ncas/alerts/TA15-051A

I think their misleading comments are going to come back and bite them more than they have already.

[EDIT - Looks like they are back peddling a little on: http://news.lenovo.com/article_display.cfm?article_id=1929

" Finally, we are working directly with Superfish and with other industry partners to ensure we address any possible security issues now and in the future. "

" By the end of this month, we will announce a plan to help lead Lenovo and our industry forward with deeper knowledge, more understanding and even greater focus on issues surrounding adware, pre-installs and security. We are eager to be held accountable for our products, your experience and the results of this new effort"

And on: http://support.lenovo.com/us/en/product_security/superfish

"Vulnerabilities have been identified with the software, which include installation of a self-signed root certificate in the local trusted CA store. ... Superfish intercept HTTP(S) traffic using a self-signed root certificate. This is stored in the local certificate store and provides a security concern. "

]

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#87
post #76

It tickles me that Superfish is a DFJ-funded [1] start-up based out of Palo Alto. Reporters are focussing on Lenovo's Chinese lineage. Yet this bubbled up out of our backyard, from our own lack of diligence (or scruples). [1] Edit: Draper Fisher Jurvetson, the $4 billion Menlo Park VC firm that backed Baidu, Hotmail, Tesla, SpaceX and Twitter.

What is DFJ?

http://en.wikipedia.org/wiki/Draper_Fisher_Jurvetson

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#88

I warned all my friends and colleagues who use Lenovos, and their answers were all the same. "Who'd be crazy enough to use the default install? First thing I did was (a fresh reinstall of Windows|install Linux)." (Edit: Obviously this is not representative of the general population, and I didn't mean to suggest it was. I was just noting that my efforts to warn people about the untrustworthiness of Lenovo were thwarte…

I'm on my 4th Thinkpad. I always do a fresh install of Linux, would never trust the pre-installed crap.

But now that I know that Lenovo is a piece of shit company with zero integrity, I don't even want to trust their hardware.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#89
post #72
post #34

Earlier quoted context omitted.

No 15 years ago Microsoft would have been the ones installing it. I think Microsoft went from being a hated software giant to sort of an underdog vis-a-vis Google, Facebook, Amazon and Apple. They are very big and strong no doubt, but I think the attitude they are projecting since switching CEO recently, their open source efforts, and such make them look pretty good PR-wise among the tech crowd.

Microsoft has done some shady things, but at no time in Microsoft's history would they have installed this.

Seems more like a Sony/Samsung move than a Microsoft one.

Re: Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless

#90

Earlier quoted context omitted.

Is it a Thinkpad, or a consumer model? The Thinkpads were never involved in this.

Well, given that they are morally corrupt enough to do this to their customers, why not expect them to have similar trojans or backdoors on Thinkpads? If we assume firmware is safe, wipe it and do a clean install from trusted media.

Can we assume their firmware is safe though?
Post reply on HN