I have no trust for Lenovo after this incident.
I have no trust for Lenovo after this incident.
You may still choose not to trust Lenovo, but it's worth noting the difference between ThinkPad and the consumer line.
If you're running Windows, you can use AutoHotkey to turn PrtSc back into a Menu key, while keeping access to the screenshot function when you use the Windows key as a modifier. Just copy this snippet into a .ahk script that you run at startup:
; Remap the PrtSc key:
; PrtSc -> Menu (like an old ThinkPad keyboard)
; Windows+PrtSc -> Screenshot of all monitors
; Windows+Alt+PrtSc -> Screenshot of current window
PrintScreen:: AppsKey
#PrintScreen:: PrintScreen
#!PrintScreen:: Send {Alt Down}{PrintScreen}{Alt Up}
This doesn't fix all the keyboard changes, but at least it makes that one pretty easy to live with.It's embarrassing to have to disclose such a thing to the public, but they did. I don't recall anything nefarious and they owned up - to at least some extent.
That is more than a lot companies can say. Is that the ONLY reason why you dis Lenovo? Because if so, it makes them that much more attractive in my book of flippant remarks
They installed spyware. That is more than enough reason to lose trust. IIRC, they did it more than once too[1].
If that isn’t cause enough, what is? Would it take pre-installed ransomware to lose trust?
https://thehackernews.com/2015/09/lenovo-laptop-virus.html?m...
I agree on principle, but Lenovo is no less trustworthy than any Smart TV manufacturer, such as Samsung, Sony, or LG.
It has become a common industry practice to subsidize consumer hardware with pre-installed spyware. The only solution here is to replace the pre-installed OS with an open-source alternative.
I would still pick Lenovo ThinkPad running Fedora Workstation over any iMac or Macbook product.
Deliberately bundling adware that injects fake results with affiliate links into search engines [1] on their machines seems nefarious in itself. The MITM of SSL connections just seems like an unexpected added bonus on top, and it took the US Department of Homeland Security to make Lenovo own up to it [2].
[1] https://thenextweb.com/insider/2015/02/19/lenovo-caught-inst...
[2] https://www.reuters.com/article/us-lenovo-cybersecurity-dhs/...
I don't consider this a technical failure, it's a business failure. One of two options remains: either nobody in Lenovo reviewed this software from a privacy and security perspective, or they did review it and the business deal overruled the security team's ability to veto it. Either way, this indicates an organizational dysfunction so severe there's no way I can trust Lenovo with my personal or business security again.
If an SSL backdoor installed by the OEM doesn't strike you as nefarious, I have beachfront property in Arizona to sell you.