I get that companies may not have bad motives. It's difficult to survey users real-life use cases. But companies have abused users with pre-installed software that's slow, poorly written, creates new vectors for exploit, shares "anonymous" information that often isn't a) secured properly or b) still personally identifiable.
Either way, the potential for damage wasn't that obvious: it could have happened to any company. (Employees often make commercial decisions without understanding the technical ramifications.)
Also, Superfish said it wasn't its fault: it blamed Komodo's tool. This amounts to a similar type of buck-passing.
I've bought a couple of Lenovo machines since Superfish, mainly because they were fantastic value for money. I also know that if I wasn't happy with the installation, I could download Windows 10 from Microsoft and do a clean installation.
You’d think so. It turns out not though.
https://www.techdirt.com/articles/20150812/11395231925/lenov...
Luckily I didn't buy any of the models that included that feature (and none of them were ThinkPads) or I would have had to run Lenovo's LSE Windows Disabler Tool from https://pcsupport.lenovo.com/gb/en/downloads/ds104370
I refuse to buy or recommend Lenovo for my family members for at least another three years yet, no matter how much they seem to have reformed. If they haven't had a repeat incident in that time I'll be glad to start considering them again.
I managed to be a ThinkPad fanboy for decades while despising IBM ;-)
Short version, manufacturers can use a feature called WPBT to load executables into your “clean” Windows installation from firmware. It’s intended for providing drivers.