Lenovo Statement on Superfish
news.lenovo.com
news.lenovo.com
I try to be measured around here, as hard as I can. I can't formulate a polite way to respond to this claim.
Lenovo, you are full of shit, and maliciously so. There is no excuse, nor forgiveness, for what you've done here.
Why would you jump to that conclusion? Apple is just a company... and through the right view-port, even something like this can appear to be "consumer oriented" to management ("we're helping customers locate products and services easier").
Recently Canonical thought it was a great idea to bake-in Amazon ads into their search lens... so ads and product placement tagged with their affiliate link were baked into your OS.
No company is immune to doing stupid things, even Apple.
Apple have also made tons of mistakes when it comes to security and privacy.
But I still have a hard time seeing Apple ever intentionally adding a feature that proxies all a user's encrypted connections to inspect the content and insert ads.
Tim Cook's recent speech at the Cybersecurity summit sounded pretty earnest to me https://www.youtube.com/watch?v=QI6DvV2muDE
I can believe that management at Lenovo simply can't understand how serious this incident is - they're unlikely to have the technical knowledge needed to understand how severe the security problem is. I'm sure there are hundreds of Lenovo engineers tearing their hair out in frustration right now. Not that this excuses the management - they should be listening to their engineers.
[1] http://www.engadget.com/2010/06/24/apple-responds-over-iphon...
I believe you are raising this point in good faith, but it verges on disingenuous to compare them.
The thrust of my argument was that most large companies are bad at communicating about technical problems because of the way the message gets filtered through management, PR, lawyers etc. It's probably fair to say that Apple hasn't ever done anything this bad - but it's also disingenuous to hold them up as an unfailing bastion of niceness and competence.
About the closest they've come to that was the "goto fail" bug from a year ago or so, and that gave every appearance of being a mistake, and Apple didn't try to claim that it wasn't a problem (although they were, as usual, pretty quiet about the exact nature of the problem).
Difference in kind. Massive, massive difference in kind.
That's not an excuse for this, but it smells like incompetence rather than deliberate malice (at least on Lenovo's part - Superfish/Komodia may be another story).
Case in point; Lenovo pitched this as a "way for our customers to find new products". This is not a problem most users have, which is why the starting point for customer-centric design should ALWAYS be user feedback. This can be collected any number of ways (focus groups, surveys, etc.) but if you ask leading questions, you're going to get the answers you wanted to hear.
I don't doubt that the people who put this product together thought that it was an enhancement to the user experience. The problem is that they didn't do the research prior to even developing the project. So the end result is a product that solves only one problem: how can Lenovo get in on some sweet advertising dollars?
Such as interoperability deficiencies, deleting competing apps from the store, etc.
Wake up.
But I've never heard about AV software itself being a vector. Where can I find out more?
This is why I'm willing to pay a bit more for things I rely upon and care about. If you were a climber, would you try to save a buck by using an off-brand, bargain rope?
And to that extent, just because you paid more for an aluminum case with exactly the same internal components doesn't somehow make it seriously better... Macbook Air's for example have notorious overheating issues that kill the laptop...
I work at a large Telco/ISP and I understand how this kind of thing happens (though I'm not excusing it).
First they come to the tech people and we explain exactly what's going on. Our managers translate it so they can understand it, and push it up with their name on it. Those Directors translate it so they can understand it and push it up with their name on it. The VPs dumb it down a bit, put their name on it and push it sideways to communications, where it goes all the way back "down" the organizational structure until someone actually makes the press release. By that time sometimes the release isn't even about the same original thing anymore.
Our company puts out press releases all the time and us tech people just shake our heads at how inaccurate and plain wrong they are.
EDIT: As Kurtz79 points out, I forgot the step where it gets translated through Legal/PR before it goes down to communications.
I mean, the statement is pretty clear and leaves little room for doubt, it would take a lot of simplification and misunderstanding to twist a proper technical analysis (provided it has been done, or even asked) to this level.
That's how you know it isn't from an engineer. We always leave a little room for doubt e.g.
"I'm 90% sure this will work!"
> We have thoroughly investigated this technology and please don't sue us.
Perhaps the real problem is that tech companies hire too many product/marketing managers, resulting in them having to cook up ridiculous money-making schemes in order to justify their own existence.
You have hit the proverbial nail very squarely on the head.
And that doesn't make it right, honest, or excusable.
Lenovo: One customer lost. More to be lost.
Lenovo also made a terrible mistake in removing the physical click buttons, but is now reintroducing them across their entire laptop range for 2015. What I see is a company willing to listen and admit their mistakes.
Can the same be said of other vendors, such as Apple?
"Oh, no, my husband's a good man. He even promised to stop beating me!"
There are plenty of valid things to criticize Apple for, but accusing them of sneaking malware onto their devices is not one of them.
While there is a chance someone may be doing something bad behind closed doors, that cannot be used as a reason for why they are worse than someone whose door we have opened and found doing something bad.
"We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns" is a laughable statement to have issued.
I can understand the legal reasons for not admitting to the security issues. But outright saying that they can't find anything to suggest they exist indicates a company I wouldn't want to do business with.
To expand on that, in this case I know enough about the subject matter to understand that it's ridiculous to suggest there aren't security concerns. But I can't guarantee this will be the case for other problems. So going forward I'd probably avoid being a customer of a company who I have positive proof is prepared to issue blatantly incorrect statements about security issues.
Why o why does "investigated this technology" even imply that somebody (technical) looked at it?
Lead: Hey vendor, is your product secure?
Vendor: Sure it is. It helps people find products they want.
Lead: Aye! That's cool. Deal!
Vendor: Aye! Let's hand it off to the mere mortals to implement the plan...
Customer (formerly known as lead): Nice doing business with you. I like we have a relationship based on trust and honesty.
Anybody can MitM any HTTPS connection coming from these laptops. Anybody! The private key is public knowledge! This is so transcendentally bad and so impossible to implement without understanding the consequences that somebody should go to jail for this.
It is not a "mistake."
This seems like a pretty good reason to drop them. When you catch somebody misbehaving, and their response is "fine, I'll stop, but it wasn't a problem" then you can't trust them at all.
Indeed. This kind of response is one of the most disrespectful things you can do to another person. "Hey, what are so upset about? Chill, it wasn't a big deal anyway!"
You probably should blame legal, not PR.
In fact, they seem to agree. I loaded the page just now, and "We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns." is no longer present in their statement.
Their statement is still unbelievably condescending and awful (and none of that has any legal bearing that I can see) but they at least removed the part where they outright denied any security problem.
Panasonic makes much higher quality hardware than Lenovo (and Apple for that matter). Panasonic also doesn't preload bloatware onto Windows.
http://www.panasonic.com/business/toughbook/semi-rugged-lapt...
Apply this to a human who did something similar.
"I'm sorry I purposefully allowed my previous employer's systems to be infected by a virus in return for payment. I'm willing to admit it was a mistake and I've taken steps to correct it."
Would you honestly hire someone like that to be a sysadmin?
If they had asked someone with a clue before, that wouldn't have happened.
They did "screw up", i.e., the financial side of the business thought it was ok to hurt the user experience in order to make more money, and the engineering side was too incompetent to realize the security risk. Why would this level of demonstrated incompetence lead you to believe that they will be better in the future?
There's also that this particular kind of compromise is basically inapplicable to hardware. What are they going to do, put a 3G radio in your laptop that broadcasts your "data" via the cell network to Belarus?
http://thehackernews.com/2015/02/hard-drive-firmware-hacking...
So no, they'll get a rootkit process running on your machine and (for instance) upload everything on your hard drive through your web browser.
Another thing they've done is to upload hacked drivers to cause other hardware connected to the infected machine to physically destroy itself.
Is that spyware Windows-specific?
I love my thinkpad... but I've always paved over the factory image the moment I got my new laptop. This is egregious beyond a doubt, but it does not affect me so I'm not worried about buying more of their laptops.
Using Lenovo's recovery images will reinstall the same bloat that it originally came with
Or procure a legit, OEM install disk/image and reload using the key affixed to the bottom* of the laptop.
*Pre-8 days, now you get to "hope" the gUEFI recognizes the media and auto-populates the embedded key for you. When(not 'if' in my experience) it doesn't, then "buy more" is the only option outside of Linux.
You can definitely use an OEM disk of your exact version with your printed serial. I too have had to procure new keys for win8 machines (did two last week that wouldn't recognize the keys on my machine)
What you may of had issue with was your OEM license being activated too many times -- if that happens, the automatic online activation will not work. You must use the phone number to activate your license, and it will ask "how many computers is this license installed on"... of course you just give the answer "one" and it activates it with no problem.
Are you referring to all flavors(Home Basic/Home Premium/Pro/Ultimate) from one disk? Installing retail/OEM from one disk has never been the case in my experience, though I have limited experience with 'retail' installs. I joined TechNet ~6 years back to obtain ISOs to reload various x32/x64/Vista/7 installs, but none of the machines' OEM keys I tried would work with the TN ISO's. If I'm not mistaken, they were specifically 'retail' ISOs.
No, Home/Pro/Ultimate are separate disks -- but OEM/Retail are exactly the same thing. You have to phone in your activation however, since OEM keys usually do not automatically activate over the internet.
Vista and up, there is no such thing as an OEM ISO image. XP had that and it was a great pain for support...
If you mean OEM in the sense of the pre-installed image on your recovery partition... that's not an "OEM" install in the same sense as the XP disks were... that's a customized image either made by something like nLite or installed on a generic factory laptop, pre-loaded with garbage, ran sysprep (to genericsize it) and imaged to a file.
The recovery image/factory image does not use the license on the bottom of your laptop usually -- it uses a factory volume license key that is pre-activated on the image. However if you try to recover that key with some key extractor, and use it to activate another installation from an official ISO, it will not work -- ie. that license will only activate at the factory. If you use the license from the bottom of your laptop, you need a genuine microsoft iso.
So long as you have a Windows 7 Pro license key on the bottom of your laptop, and use a Windows 7 Pro ISO, it will work.. or Home and Home, etc...
And... you appear to be absolutely correct.
"Vista and up, there is no such thing as an OEM ISO image. XP had that and it was a great pain for support..."
I was not aware OEM & RETAIL installation media were merged, cannot locate any search results verifying this, but I cannot find any recent issues being discussed either. Site where I buy software still has the categories distinguished & separate, but I never considered the media became one and the same w/ only distinction being the key itself(and all rights afforded Retail over OEM). I had numerous problems installing 7 when it appeared on consumer devices before I did any machine builds w/ 7(and made images of installation media that came with their licenses), hence my subscribing to TechNet(R.I.P.) before Digital River links became ubiquitous... and yeah, I have a dozen+ variants of XP due both to it's OEM/RETAIL duality plus the never-ending sfc /scannow prompt: "please insert original installation media" if XP received any Service Packs since original installation.
I do now recall unlocking Vista & 7 disks to install any flavor now that you mention nLight... another contributor to my lapse. Plus, I did find official MS pages that support your last point on unique disks for each flavor... I thought it was just for Enterprise.
EDIT:
"You have to phone in your activation however, since OEM keys usually do not automatically activate over the internet."
After activation failure, you can opt to insert a different key & retype the same key a 2nd time for online activation. That always irked me, I thought it was a bug.
Typically the "OEM" purchase of the ISO Disk comes in just a plain white envelope (with COA sticker somewhere on it) and "no official microsoft support" since it's intended for "systems builders" who microsoft expects to have their own support for consumers. A lot of people who build their own rigs choose this option because the "OEM" package is usually $10-$30 cheaper. The "Retail" packaging just comes with the fancy case with color inserts, etc... and "official microsft support".
If you are building your own rig, you're probably unlikely to call Microsoft for anything. If you are some company's internal-IT, you're unlikely to call Microsoft for anything.... Heck, if you are installing your own Windows installation, you're unlikely to call Microsoft for anything... So i just always buy the "OEM" packaging when I need a new license.
So the difference there is really just the packaging the ISO/Disk comes in and whether or not it has "official" support by Microsoft. Otherwise the ISO image on the disk is identical. :)
https://www.thurrott.com/uncategorized/1146/clean-pc-walkthr...
The, it didn't effect me because I reformatted is kind of a "First they came for the communists..." argument.
Oh and that I run a website over https matters too. I want that all users have the same expectation what that means.
I get it if I'm wiping out and putting on Linux or something, but that always seems like I'm wasting something I've already bought.
So, that communication your girlfriend might send you over https is not private any longer.
Go figure.
Never purchased a Lenovo but I was bent on using one for my next machine. No longer. Their lies about it "not being a risk" have put the affected customers at immense risk.
Just because others are doing it, does not make it right.
But what the fucking fuck have people not understood about this issue?
Someone might run open, free access points, sucking people in to connect and then they fucking MITM everything - inclusive that money transfer from your relative to you. How about that? Yes, you might be affected by this huge fuck up from Lenovo.
The HN crowd is such an insignificant percentage of the overall population that I don't see how word of mouth will have any impact.
You don't support lawsuits (all those pricks abusing the courts, extorting money from companies!)... right up until the hot second a company screws you, and then the courts are an appropriate recourse.
Maybe you could consider becoming a decent human being, learning some empathy, and realizing that perhaps other people have used the courts as recourse because they, too, were screwed by a company. Labeling lawsuits as an abuse of the court system or other laws is company defense 101.
It does not mean or imply "opposed" or "disdainful" or "disinterested", at all.
I'm giving Lenovo the benefit of the doubt here. Look at all the potentially malicious crap Dell, HP, Compaq, and others have installed on computers over the years.
Any experienced computer user should know and want to wipe the hard-drive and reinstall as soon as you get the computer, preferably from trusted sources, I'm not sure Microsoft's rules on customizing their reinstall disk. I wouldn't trust the reinstall partition either.
You have to also consider that the Chinese government might see all the news about NSA and US government hacking and intercepting hardware and they could require or secretly implement bugs into almost any Chinese made product, that's always been an unfortunate concern with Lenovo.
If Lenovo would push for more open standards of all computer components and have independent parties verify their internal processes, then that would go a long way to improving their credibility after this incident.
http://www.wired.com/2012/07/ff_kaspersky/all/
If this was going on with a US OEM, people would assume the NSA. But with Lenovo (which the US government refuses to buy btw) and Huwai and other non-vendors for the USG, HN'ers have regularly defended them and claimed the US was being paranoid or protectionist. How the hell do you think a fucking MITM gets onto a production image? This is financial suicide for Lenovo and they know it. This has all the telltale signs of government collusion. The CCP has a lot more to gain from stuff like this than Lenovo has to lose. How many people have been compromised from ship date until the day this gets uninstalled? Millions? For how many months? Years? That's a lot of SSL sniffing available to the CCP.
They are so big and bureaucratic, half the time they don't know who is working on what.
This behavior is still inexcusable.
Somebody should be fired for putting this garbage on computers to "enhance the users experience."
> The relationship with Superfish is not financially significant; our goal was to enhance the experience for users.
Right. You loaded adware onto users' computers, not for financial gain, but to enhance the experience for them.
"We will not preload *this* software in the future."
and what they don't say: "We will not preload *such* software in the future."
(Emphasis added)[Superfish technology sends your data to a third party ad server. We then use this data to create behavioral profiles on you, we process this data, and we monitor it. Finally we record all this data in our backups for up to 10 years.]
is consistent with:
To be clear, Superfish technology is purely based on contextual/image and not behavioral. It does not profile nor monitor user behavior. It does not record user information. It does not know who the user is.
edit: clarified.
Pretty egregious misrepresentation from Lenovo if that's true.
> The relationship with Superfish is not financially significant;
Again, with my tinfoil hat on, I believe this. I believe that either Israeli (check out Superfish's background and connections) or Chinese governmental groups have forced Lenovo into loading this awful malware onto its machines.
> our goal was to enhance the experience for users.
Not their goal in loading adware, but their goal in general. They are drawing a line (or semicolon) between what they wanted to do, and what the dark and mysterious forces behind Superfish forced them to do.
Again, tinfoil hat. This is all very conspiracy theory-ish.
Wait, your IT department just frantically rolled out clean disk images to the whole org? That's a funny coincidence...
It's probable that their lawyers told them to make this claim to lessen their exposure to lawsuits. If they admitted any kind of problem they'd be in hot water, but now the burden is on anyone bringing a suit to prove them wrong.
The first thing we do, let's kill all the lawyers.
Have a look at code delivered by Superfish:
https://www.superfish.com/ws/sf_preloader.jsp
https://www.superfish.com/ws/sf_code.jsp
And grep for track and retarget. Just two snippets:
var url = sfDomain + "trackSession.action?userid=" + similarproducts.b.qsObj.userid + "&sessionid=-10&action=ud_host_failed";
and: function isRetargetingEnabled(){
if( similarproducts.b.enableRetargetingUnit && !isRetargetingBlackList()){
return 1;
} else{
return 0;
}
}"So what's your face doing on all of these security cameras at the scene of the crime?"
"... uh..."
Tracking is more ambiguous a word and I couldn't find where they define the userid. But however it is generated, it reads like it's unique. And in order to retarget users, you'd have to track which products they've viewed in the first place, that would imply storing browsing history (they deny storing user info as well) and uniquely identifying users across websites.
Given the coding style, I don't think the person(s) who wrote this code is/are doing anything clever other than what it seems.
Perhaps this is some sort of style thing specific to javascript, but wouldn't:
function isRetargetingEnabled(){
return (similarproducts.b.enableRetargetingUnit &&
!isRetargetingBlackList());
}
be the better way to write it? Sure say what you want about micro-optimizations, but the function appears to be used in a boolean context, so shouldn't it just return the if condition? Things like this are why I have trouble trusting security claims.EDIT: Fixed double-negative
I also wouldn't read too much into it. It's unlikely that the same person wrote all the code involved, and many smart people I know write these kinds of functions, no matter how much I complain about it.
"Superfish will be removed from Program Files and Program Data directories, files in user directory will stay intact for the privacy reason. Registry entry and root certificate will remain as well. The Superfish service will stop working as soon as it is uninstalled via above process, and following reboot."
Per Lenovo's removal instructions [1], the compromised root certificate will still be installed and trusted. This is completely laughable.
[1] http://forums.lenovo.com/t5/Lenovo-P-Y-and-Z-series/Removal-...
Do a simple tracker on a desktop, and people freak out. But all you have to do is change the form factor and UI metaphor to mobile and people are absolutely fine with constant location tracking, ambient sound being uploaded to the cloud (SIRI, etc.), a camera and a microphone that can be activated by all kinds of apps while the device is in your pocket, and a constant 24/7 Internet connection. You could never even approach that level of invasiveness on a desktop or laptop.
A desktop/laptop is a computer. A smartphone is a computer. Why the different reaction?
I wonder if it's a generation gap thing. Older people tend to use mobile devices less than younger people. Are the younger generation this oblivious?
Same phenomenon holds by the way with regard to jailed devices. Way back when Microsoft tried to introduce something called "trusted computing," which was basically just code signing. Everyone flipped the hell out and they shelved it. But mobile devices can't run software that isn't tethered to their app stores, and everyone is totally fine with that. Different form factor, different universe?
It also seems related to brand. When you sign into Chrome with your Google ID, Google tracks everything you do. But that's Google, not some random little foistware company, so that's okay I guess. Same goes for Safari and iCloud, etc.
The Lenovo adware wants to hijack SSL connections. To do so, it installs its own CA, and the private key for that CA can be (and has been) extracted. This means that if you own such a laptop and access your bank's SSL website from a random coffee shop, anybody could MitM you, since they can use the publically available "private" key of the rogue CA to impersonate your bank.
Smart phones enable turn-key surveillance-based dictatorships beyond anything we've ever seen in the west, but unlike this Lenovo thing, it is not an immediate threat. Hence people react differently to it.
They're still two different classes. Smartphones (at least the mainstream Android, iOS and Windows platforms) aren't even self-hosting yet, so they're definitely in their infancy and unlikely to displace the microcomputers we have until said shift occurs, regardless of widespread commentary to the contrary.
By the way, "trusted computing" was backed by a ton of other companies besides Microsoft (I don't even think Microsoft were remotely the first), and it is most certainly not dead in the slightest.
Another, maybe smaller part, is trust. I for one sign into Chrome with my Google ID and enable all location services, etc. on my Android phone because I still trust Google and the Don't Be Evil mantra. I haven't been convinced yet that they're a bad actor (OTOH I can't say that about Apple). I admit it's probably very subjective.
To the best of my understanding, Siri doesn't do this. Siri listens, locally and on-device, for the hot phrase. (I know that the Moto X does that for 'Okay, Google Now'.)
Anyway, to the other points: I get something for providing information to Google. My location isn't terribly important to me and the benefits outweigh the risk. Ditto an online internet connection. My phones, iPhone and Android alike, both run whatever software I want--Cydia was the first thing I installed on my iPhone and Android accepts applications without qualm. (And I don't use applications that can turn the camera or microphone on without my knowledge.)
This is spying on my e-mail and my bank. It has literally no positive attributes. There's just such a massive difference to me that I get confused at your core claim.
This is a massive, well-established company deliberately introducing a gigantic security hole into all secure internet services, including the ones you use for online payments, banking, and governmental services. It's a security hole that can be exploited by anyone with moderate technical knowledge, and it was all done for the sake of showing you ads.
Seriously?!
So then you spam the world with "Important message from Lenovo" and hope they click on https://len0v0.com and install your important update
This really sucks because I used to recommend Lenovo workstations and ThinkPad laptops to people; it really is good hardware at a decent price. I know this certificate/spyware issue was only on the consumer side, but it stains their entire reputation as far as I'm concerned. When my wife's Lenovo IdeaPad finally dies, we're not going to get another Lenovo like we planned.
"Uninstalling Superfish Visual Discovery
Go to Control Panel > Uninstall a Program
Select Visual Discovery > Uninstall
Superfish will be removed from Program Files and Program Data directories, files in user directory will stay intact for the privacy reason. Registry entry and root certificate will remain as well. The Superfish service will stop working as soon as it is uninstalled via above process, and following reboot."http://forums.lenovo.com/t5/Lenovo-P-Y-and-Z-series/Removal-...
This was just edited, here is the post before that: https://web.archive.org/web/20150219151726/http://forums.len...
"The relationship with Superfish is not financially significant; our goal was to enhance the experience for users."
Right.
I would prefer for this to be a lie than for it to turn out for this statement to be true. Surely nobody at Lenovo honestly belived that ad injection improved user experience?
Take Uber, for example. It's apparently a popular ride-sharing service, which I've only heard of recently due to a bunch of articles about them getting into trouble with the law. So how did that service get to be so popular to begin with? How did people first hear of them? I'm guessing that there were lots of banner ads for them all over the web, which I've never seen.
Of course, my curiosity as to what goods and services I might be missing out on is not strong enough to cause me to turn off Adblock, because good lord, the web user experience is horrible without it.
There was one time when I visited my mother. We started her instant messaging program, and we were presented with special offers. I recognized it as such within half a second, so I almost automatically checked the 'Do not show this again' checkbox.
My mother alarmed me: "No, do not make it go away! I want to see the offers, they're useful!"
I was mindblown.
Another example: I have snail mail advertisements. But my girlfriend, who's living with me now, asked me to sign up for advertisements such as supermarket special offers. Another mindblown.
Why would you not want to sign up to know about what discounts are available at your local grocery store, especially if you frequent it weekly.
I don't really understand why "can be easily faked" is how you're justifying this.
Also records are kept for mail regarding where it was received by the post office (which likely has security cameras), when, who is on the return address and the recipient. There is physical evidence of who has touched a piece of mail such as fingerprints, hair, DNA etc.
This is part of why you don't get 50 letters from nigerian princes each day
So for example, you didn't learn about the existence of cameras via ads - you probably saw your parents or friends shooting photos when you were a child. And you know that the ads of cameras you see on the web are offering subpar products, and you're better off searching for a camera that fulfills your needs yourself.
Another example, of a relatively new category - iBeacons. You probably read about them on the Internet, or maybe in a magazine like The Economist. Sure, maybe you read an infomercial, but what you've learend is that there is this new category of products, and that they can help you make phones more context-aware. But if you're thinking about what beacons to buy, you are again better off researching yourself and consciously ignoring anything that looks like an ad.
It's definitely better than the ads that ghostery blocked, but ads aren't going away and they were still important to the discovery process.
Is that Canon ad on HBR relevant to me? Are Canon cameras subpar?
I hate many ads too but I'll seek out discounts when I think they might exist.
My mother recently told me how she's tired of keeping track of prices (or price/quality tradeoff) in 5+ different shops - she can save a lot of money and buy good quality products at the same time as long as she knows what to buy where. But she's doing bulk shopping. I probably wouldn't bother walking around the hood to get one item cheaper.
In contrast, Internet advertising offers me pretty much nothing of interest.
¹ ...of our targeted advertising platform
I can see the marketing folks honestly believing this. See, the problem with people in marketing is that they come up with ideas that sound good in theory but neglect to consider the implications.
"Wouldn't it be great if I was presented with offers to buy things based on context clues in the web pages I'm browsing?"
"Wouldn't it be great if I didn't have to enter passwords all the time?"
After the marketing brainstorm session the engineers are asked "can this be done?" And the answer is usually "Yes, but..." This is the point at which the marketing droid zones out. "Make it so!"
So yes, I do believe someone in marketing thought this was a great idea. And if it worked perfectly without compromising security, it probably would be a good idea. But there's always compromises in technology, and the marketers either can't grasp or don't care about the consequences.
Good business is about providing value for proper compensation. If you're trying to trick your customer into paying more money for less value, you're just scamming them.
But here, in this particular case, you clearly have bad intentions with a side order of criminal negligence.
See the funny thing is that I've worked in the PC making business and the parts business (Newegg) and the way this software makes it into the preload is not because of marketing, it's a product or finance decision. Hardware is a low margin business so you get paid to add in some pre-installed software and structure some revenue sharing deals. Lenovo isn't lying when it said that it wasn't financially meaningful; in fact, that's probably why they stopped installing it (not because they did some survey of users, etc.).
I don't think any reasonably competent marketer would ever suggest installing some adware as a "feature" so that they could market it. The fact that people are only finding out about this Superfish now meant that Lenovo and Lenovo marketing didn't advertise it's existence. Can someone show me some marketing material that say's "Lenovo PCs, now with more Superfish to enhance your online shopping experience."?
That's not really where I was going with it, just pointing out that sales and marketing start out with reasonable "what if I could..." scenarios and don't really care about the implementation.
> I don't think any reasonably competent marketer would ever suggest installing some adware as a "feature" so that they could market it.
You're right, because they don't think at the implementation level. What I think _did_ happen, if my experience is any indication, is that someone said "I think showing users suggested products would be a tremendous value add! Let the eggheads figure out how to do it." What you end up with is what needs to be done at a technical level in order to fulfill marketing's requirements. It ain't always pretty.
Sounds a lot like Google ;-)
There's a reason why security-conscious folks spend an enormous amount of money on the stuff that we buy for a couple hundred bucks. I'm sure that the NSA pays thousands for $100 hard drives.
Heart of the matter is that most consumers - whether personal or business users will have little to no visibility into this. And, even a smaller fraction will have the technical chops to remove this garbage unless there's a tool that's openly presented to them.
Since there are a ton of small businesses that purchase and consume laptops just as the come out of the box, I'm really interested in the industrial espionage potential with this.
Couple in all the PRISMish like revelations over the last year and a half, and I simply have trouble putting much faith in their, "oh, it's just to show better ads, sorry..." statement.
There's certainly an unrealized support cost. But in my experience, it's pretty common to see several different manufacturers and OSs across a small business. When they need a new laptop, they're either picking up what's cheap at Best Buy or handing down machines when the boss gets a new one.
I'm sure that Lenovo has some really smart people that right now consider if they should dust off their CV and jump ship instead of working with morons.
This kind of stupidity can really destroy morale of technical teams within an organisation.
But yeah, the removal instructions mention that the certificate won't be removed, which is quite dangerous.
EDIT: And users removing the cert would be unable to load https pages, which is a tricky situation.
What alternative linux laptops are there? (aside from macs)
upower says the battery is designed to store up to 48Wh, with a maximum design capacity of 53Wh.
Is there any hardware in it that doesn't work in Linux?
If only they had a trackpoint style pointing device, that would be my perfect next laptop!
I think it has more to do with the fact that a lot of people just don't like the Trackpoint or (more likely) won't give it a shot, so manufacturers aren't going to invest the time and money to put it on their laptops.
Personally I think the Trackpoint is the greatest thing ever, but I worked at IBM for a long time. Pretty much anyone who has had to use Thinkpads for an extended period of time ends up loving the Trackpoint. But regular people just don't want to give it a shot.
The 840 G1 I'm trying now has some ACPI and ATA issues currently on any stock kernel (google for more details). HP is definitely not even trying to test his high-end laptop line on Linux.
I was quite ok with the Thinkpad line, but this move from Lenovo would now tend me to Dell.
It's more comparable to a macbook pro than the air though.
Also this 20% off coupon works: MXPX2T1N9HGH12
This is roughly what Lenovo is trying to pull off here.
> Superfish was previously included on some consumer notebook products shipped in a short window between September and December to help customers potentially discover interesting products while shopping.
This is the compromise being offered. They're claiming, "We didn't violate your privacy, we didn't violate your security, we just wanted to help you discover interesting products."
Superfish opens up all sorts of security holes and privacy concerns, but it's probably true that this wasn't Lenovo's intention (not yet, anyway). But to accept this as a compromise would be to give Lenovo the thing they want in the first place: to serve ads into our web searches. And that in itself is deplorable. It is not acceptable for companies to force their agendas on us.
Lenovo's only defense here is that they were doing something disgusting. We should not accept this compromise.
https://forums.lenovo.com/t5/Lenovo-P-Y-and-Z-series/Lenovo-...
Ugh. Patronising, misleading and evading the point all in one answer. This was a horrible thread to read.
Here's the complaint form for Massachusetts: http://www.eform.ago.state.ma.us/ago_eforms/forms/piac_ecomp...
Some state AGs are active on Twitter too, which might get more direct visibility.
The Superfish cert is there, however the VisualDiscovery service that injects the adds was at some point disabled as I could only find remnants of it in form of INI files and registry keys.
A quick fun fact, There are two encrypted INI files located in the Windows Folder :
A.) VisualDiscovery.INI
B.) VisualDiscoveryOff.INI
If that doesn't tell you everything you need to know about the guy that developed this shit then I don't know what will.
I'm on Lenovo's mailing list and haven't seen a similar statement in my inbox with remedial instructions.
I was only half-lucky with Superfish. I bought my Y50 before Xmas and removed Superfish and all other non-essential software but didn't know about the certificate, which I deleted today.
Sadly, I don't think the typical non-technical Lenovo user is even going to find out about this or know how to fix it.
"It does not profile nor monitor user behavior. It does not record user information. It does not know who the user is. Users are not tracked nor re-targeted."
from someone who refers to ad-ware as "...to help customers potentially discover interesting products while shopping".
Barf.
> We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns.
A bald-faced lie!
> our goal was to enhance the experience for users
A bald-faced lie! Adding ads to a page cannot enhance user experience!
I'm on, I think, my 4th ThinkPad. A loyal customer.
Stop treating us like shit! This is completely unacceptable.
Issue a real apology and start firing people, or shut the fuck up.
You wouldn't buy a car that came painted with advertisements on the side!
And I'd hazard a guess (with no evidence) that very few people paid that extra cost. We undervalue our own attention, assuming that we can easily ignore adverts, so ad-supported products are disproportionately successful (preinstalled bloatware is just a special kind of advertising).
Does anyone know how well Amazon Kindles with 'Special offers' are selling?
I don't believe that for a second.
I know it is lucrative to preload but I really wish this practice would just die. In the long run, they are just hurting their business.
One way to read this is they have not seen any evidence that people have actually been hacked in the wild. They may understand perfectly well that it is now trivial to do this but no one's actually reported yet that they had thousands of dollars stolen due to using online banking on a compromised Lenovo machine on public Wi-Fi.
Roll on the class action lawsuits.
What's the best way to tell Lenovo they fucked up? I mean, I can vent over social media all day but will they even pay attention?
In other words, they just acknowledged it without admitting fault or liability.
In essence, a root certificate with known private key is as dangerous as a worm that infected your computer. Maybe even more dangerous.
On a PC I do a Linux install and go through some extra settings.
On Android I install CyanogenMod with an IPtables firewall. The number of apps that try to raid your address book on Android is mind-boggling. When you set Privacy guard to "ask" instead of "deny" you will have so many popups that the phone is bogged down for a couple of minutes after startup.
Apparently a wildcard SSL certificate valid for every domain on the internet installed in a certificate store isn't a security concern.
Apparently said SSL certificate having a extractable private key installed within a user certificate store isn't a security concern
And apparently leaving said certificate behind in the certificate store even after uninstalling the crapware (according to a very reliable InfoSec Taylor Swift) isn't a security concern.
Wow? Wow.
Surely the endless bundled crapware from every OEM just gives Windows a bad reputation in the long term. The popularity of chromebooks now are a testament to that.
That would probably put Lenovo out of business, actually. Might get other OEMs to take notice too :)
Under the US Government-imposed anti-trust rules, Microsoft wasn't even allowed to charge the top OEMs different prices. Otherwise it could have discriminated against the "bad" ones.
What Microsoft does instead is offer Signature editions that are crapware free....
http://forums.lenovo.com/t5/Lenovo-P-Y-and-Z-series/Removal-...
"This article will be updated with additional instructions on clean up of deactivated files and removal of certificate shortly."
This was just edited in, here is the post before that: https://web.archive.org/web/20150219151726/http://forums.len...
So, Lenovo, why should we remove this certificate after all? Any security concerns perhaps?
I used to recommend Lenovo as a good laptop for work, with great quality hardware for the price but since a couple years my vision is shifting towards "Lenovo isn't what it used to be, I think we should stop ordering from them..." I had a lot of problems with defective hardware lately even on Thinkpad...
This news just adds to the pile of deception I had with Lenovo lately.
[1] http://www.microsoftstore.com/store/msusa/en_US/pdp/Lenovo-Y...
Can't get any better than that!
Seriously, there were so many different ways they could have gone with this and saved face, but they just decided to hunker down. Sad.
The apology always seems to make it worse.
My X1C was ordered on Feb 4th, and shipped Feb 9.
I believe that my machine had this malware installed when I received it. On firefox, websites that would not normally have many ads, were filled with ads to the point where I couldn't use the sites.
I am unable to prove my claims, as I formatted the HD and installed Linux to get rid of all the obvious bloat-ware.
I really enjoy the laptop. But if I was less tech savvy and unable to format/installLinux I would probably have returned the machine (the ads were really really intrusive)
We've heard this song and dance before. Excuse my skepticism, but I don't believe you and until we can see some source code, I won't believe you.
What did this choice look like? Were users prompted to remove the cert if they didn't want it?
Wow how thoughtful and helpful of them.
I don't understand the point of bloatware. Are the manufacturers making a ton of money off of them or something? How much could bloatware writers possibly be offering to make it worth uglifying your brand?
There of course is a point that each manufacturer would like to provide some added value through software that would set them apart from other vendors - because hardware competition is so fierce - but unfortunately their priorities for selecting the vendors they use are really bad. Much of the crap is just horrible, and I don't recall seeing anything really useful recently.
But now, there's no way in hell I'd buy a Lenovo. Trust is not easily regained once broken.
It's not adware, it's a feature!