Lenovo to pay $7.3M for installing adware in laptops
hackread.com
hackread.com
For those of you in the adware space, would you pay >$10 per head to install your adware onto a computer? My guess is absolutely.
Also, they sold their customers pretty cheap, so the combined fines likely significantly exceed the profit from the deal: https://www.forbes.com/sites/thomasbrewster/2015/02/27/lenov...
While I do think the punishment should be significantly more severe (including jail time for executives), I suspect the scandal has made companies aware that this is a bad idea.
I still don't get why it didn't hurt them more in the enterprise space (read: why large companies didn't institute a strict "no lenovo" policy for a couple years). That would have been way more effective than fines.
Using vendor OS images is a rookie mistake in the first place.
I kind of wonder how many people were like, "pre-install adware on PCs? Why didn't I think of that?!?"
When I buy PCs, I only buy either the business line from Dell or from the MS store.
[0] https://news.lenovo.com/article_display.cfm?article_id=2013
Vendor-bloatware has been bad since Windows 7 but now that even Microsoft chose to ship Windows itself with ads, pre-installed garbage like Candy Crush Saga and that annoying Cortana I can't imagine going back to it.
You can get £20 books for 50p, because either the person has finished using the book, and there are lots of books; or because the person got the book free (as a gift generally) and didn't really want it; or because they bought a copy and got a second copy gifted, etc.
Furthermore, this is not one vendor selling one ‘stolen’ item, it is many, selling many keys. This makes it seems like a legitimate channel for keys to the average consumer. It also makes eBay more responsible if you ask me. It seems to me as if they are making a profit from those sales. If they truly are illegal keys then they should probably do something about it.
So why am I wrong here?
A rather unfair comparison, don't you think? That's like saying "I got a really good deal on a Macbook, all I had to do was pick it up and sprint out of the Apple store!"
The consumer has the responsibility to check the validity of the product, sure, but this is ridiculously unfeasible for digital licenses. A lot of companies actually do buy these 10$ keys and I don't blame them.
https://law.stackexchange.com/a/1848/1059
you're dismissive, but they've specifically claimed the legal right to sell your usage data. it seems pretty clear to me.
I personally don't want to support what Microsoft is doing with Windows so that's why I bought it from a shady ebay seller.
Of course, the more ethical solution would have been to talk her into a GNU/Linux machine but I don't have the time and energy to play IT support for the next six months.
I may just put my money where my mouth is and start the break up with Google too, as painful as that will be. I just dont feel like I align with these fucking companies at all anymore.
[1]https://support.lenovo.com/us/en/product_security/superfish
Three times. They don't deserve to exist anymore.
Edit
https://www.makeuseof.com/tag/security-failings-demonstrate-...
[1] https://www.theregister.co.uk/2015/08/12/lenovo_firmware_nas...
pressroom: https://news.lenovo.com/pressroom/press-releases/lenovo-stat...
the guardian: https://www.theguardian.com/technology/2015/aug/14/lenovo-se...
Do you have a citation for Lenovo's competitors installing comparably vulnerable malware?
[1] https://threatpost.com/lenovo-hit-with-criticism-over-second...
We can of course say they shouldn't have trusted it, but honestly, should it be normal to expect the manufacturer of the machine to be malicious?
Not to mention the other commenters pointed out that they used the firmware to reinstall the malware even on otherwise clean images, so even enterprises could've been at risk.
You can't trust the hardware, microcode or firmware either.
It’s great that the countermeasures worked this time, but Lenovo is still your adversary. They deserve the same response as any other insider who tries to MITM your traffic: immediate termination, a thorough search for any remaining implants, and an FBI battering ram through their door.
https://arstechnica.com/information-technology/2015/11/dell-...
Apparently hp also
https://www.computerworld.com/article/3238512/microsoft-wind...
The dropper was passive, abusing a Windows mechanism designed for installing vendor software, in which Windows looks for such software and executes it.
Linux does not go diving in UEFI looking for executables to run.
IMO they'd deserve _way_ more than that. The precedent is scary.
This is, the 7.3 MUSD to be paid, plus the prorated expenses to compensate the employees handling the case, plus court fees, plus travel expenses, etc., but ignoring factors like lost sales, other fines and settlements, etc.; is the final figure still around 7.3 MUSD, or would it be significantly more?
Lenovo's LSE used UEFI to redeploy the binaries thanks to Microsoft's wonderful Windows Platform Binary Table.
Microsoft's default Disk Management system cannot remove EFI partitions (in all cases), and you need to.
I do this on 100% of my computers now. I thought there was a risk of losing some functionality like the touch screen, but everything works and far better than when I bought it.
Cortana still sucks though.
The problem is pre-installed crapware. Windows seems fine.
Thinkpad had a shot at being the world's most loved laptop, by developers and businessman on the go.
Passion for great products and great user experience is clearly not what drives the thinkpad product line today, and that is regretful. It is one of those business that I would love to run.
But even then, why should anyone at IBM care what happened to the brand after they sold it? I know some creators love their product lines and such and care about posterity, but, IBM!
Even then it's like saying iPhones manufactured by Foxconn are only badged by Apple. The original IBM Thinkpads all the way up to the T43 were developed by IBM and built/designed significantly better than the ones today. Also a large selling point of the old models was the software (!), which made some things easier.
$249 is still serious money for most families.
If you're purchasing a computer with Google software on it aren't you already handing everything to Google?
So is a Chromebook really an alternative if you're rejecting Lenovo tablets for poor security/privacy?
I've been interested in Chromebook hardware but have rejected them for security reasons previously. I'd be interested to hear other people's opinions on the mater.