I try to be measured around here, as hard as I can. I can't formulate a polite way to respond to this claim.
Lenovo, you are full of shit, and maliciously so. There is no excuse, nor forgiveness, for what you've done here.
I try to be measured around here, as hard as I can. I can't formulate a polite way to respond to this claim.
Lenovo, you are full of shit, and maliciously so. There is no excuse, nor forgiveness, for what you've done here.
I work at a large Telco/ISP and I understand how this kind of thing happens (though I'm not excusing it).
First they come to the tech people and we explain exactly what's going on. Our managers translate it so they can understand it, and push it up with their name on it. Those Directors translate it so they can understand it and push it up with their name on it. The VPs dumb it down a bit, put their name on it and push it sideways to communications, where it goes all the way back "down" the organizational structure until someone actually makes the press release. By that time sometimes the release isn't even about the same original thing anymore.
Our company puts out press releases all the time and us tech people just shake our heads at how inaccurate and plain wrong they are.
EDIT: As Kurtz79 points out, I forgot the step where it gets translated through Legal/PR before it goes down to communications.
I mean, the statement is pretty clear and leaves little room for doubt, it would take a lot of simplification and misunderstanding to twist a proper technical analysis (provided it has been done, or even asked) to this level.
That's how you know it isn't from an engineer. We always leave a little room for doubt e.g.
"I'm 90% sure this will work!"
> We have thoroughly investigated this technology and please don't sue us.
Perhaps the real problem is that tech companies hire too many product/marketing managers, resulting in them having to cook up ridiculous money-making schemes in order to justify their own existence.
You have hit the proverbial nail very squarely on the head.
And that doesn't make it right, honest, or excusable.
> The relationship with Superfish is not financially significant; our goal was to enhance the experience for users.
Right. You loaded adware onto users' computers, not for financial gain, but to enhance the experience for them.
"We will not preload *this* software in the future."
and what they don't say: "We will not preload *such* software in the future."
(Emphasis added)[Superfish technology sends your data to a third party ad server. We then use this data to create behavioral profiles on you, we process this data, and we monitor it. Finally we record all this data in our backups for up to 10 years.]
is consistent with:
To be clear, Superfish technology is purely based on contextual/image and not behavioral. It does not profile nor monitor user behavior. It does not record user information. It does not know who the user is.
edit: clarified.
Pretty egregious misrepresentation from Lenovo if that's true.
> The relationship with Superfish is not financially significant;
Again, with my tinfoil hat on, I believe this. I believe that either Israeli (check out Superfish's background and connections) or Chinese governmental groups have forced Lenovo into loading this awful malware onto its machines.
> our goal was to enhance the experience for users.
Not their goal in loading adware, but their goal in general. They are drawing a line (or semicolon) between what they wanted to do, and what the dark and mysterious forces behind Superfish forced them to do.
Again, tinfoil hat. This is all very conspiracy theory-ish.
Lenovo: One customer lost. More to be lost.
Lenovo also made a terrible mistake in removing the physical click buttons, but is now reintroducing them across their entire laptop range for 2015. What I see is a company willing to listen and admit their mistakes.
Can the same be said of other vendors, such as Apple?
"Oh, no, my husband's a good man. He even promised to stop beating me!"
There are plenty of valid things to criticize Apple for, but accusing them of sneaking malware onto their devices is not one of them.
While there is a chance someone may be doing something bad behind closed doors, that cannot be used as a reason for why they are worse than someone whose door we have opened and found doing something bad.
"We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns" is a laughable statement to have issued.
I can understand the legal reasons for not admitting to the security issues. But outright saying that they can't find anything to suggest they exist indicates a company I wouldn't want to do business with.
To expand on that, in this case I know enough about the subject matter to understand that it's ridiculous to suggest there aren't security concerns. But I can't guarantee this will be the case for other problems. So going forward I'd probably avoid being a customer of a company who I have positive proof is prepared to issue blatantly incorrect statements about security issues.
Why o why does "investigated this technology" even imply that somebody (technical) looked at it?
Lead: Hey vendor, is your product secure?
Vendor: Sure it is. It helps people find products they want.
Lead: Aye! That's cool. Deal!
Vendor: Aye! Let's hand it off to the mere mortals to implement the plan...
Customer (formerly known as lead): Nice doing business with you. I like we have a relationship based on trust and honesty.
Anybody can MitM any HTTPS connection coming from these laptops. Anybody! The private key is public knowledge! This is so transcendentally bad and so impossible to implement without understanding the consequences that somebody should go to jail for this.
It is not a "mistake."
This seems like a pretty good reason to drop them. When you catch somebody misbehaving, and their response is "fine, I'll stop, but it wasn't a problem" then you can't trust them at all.
Indeed. This kind of response is one of the most disrespectful things you can do to another person. "Hey, what are so upset about? Chill, it wasn't a big deal anyway!"
You probably should blame legal, not PR.
In fact, they seem to agree. I loaded the page just now, and "We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns." is no longer present in their statement.
Their statement is still unbelievably condescending and awful (and none of that has any legal bearing that I can see) but they at least removed the part where they outright denied any security problem.
Panasonic makes much higher quality hardware than Lenovo (and Apple for that matter). Panasonic also doesn't preload bloatware onto Windows.
http://www.panasonic.com/business/toughbook/semi-rugged-lapt...
Apply this to a human who did something similar.
"I'm sorry I purposefully allowed my previous employer's systems to be infected by a virus in return for payment. I'm willing to admit it was a mistake and I've taken steps to correct it."
Would you honestly hire someone like that to be a sysadmin?
If they had asked someone with a clue before, that wouldn't have happened.
They did "screw up", i.e., the financial side of the business thought it was ok to hurt the user experience in order to make more money, and the engineering side was too incompetent to realize the security risk. Why would this level of demonstrated incompetence lead you to believe that they will be better in the future?
There's also that this particular kind of compromise is basically inapplicable to hardware. What are they going to do, put a 3G radio in your laptop that broadcasts your "data" via the cell network to Belarus?
http://thehackernews.com/2015/02/hard-drive-firmware-hacking...
So no, they'll get a rootkit process running on your machine and (for instance) upload everything on your hard drive through your web browser.
Another thing they've done is to upload hacked drivers to cause other hardware connected to the infected machine to physically destroy itself.
Is that spyware Windows-specific?
I love my thinkpad... but I've always paved over the factory image the moment I got my new laptop. This is egregious beyond a doubt, but it does not affect me so I'm not worried about buying more of their laptops.
Using Lenovo's recovery images will reinstall the same bloat that it originally came with
Or procure a legit, OEM install disk/image and reload using the key affixed to the bottom* of the laptop.
*Pre-8 days, now you get to "hope" the gUEFI recognizes the media and auto-populates the embedded key for you. When(not 'if' in my experience) it doesn't, then "buy more" is the only option outside of Linux.
You can definitely use an OEM disk of your exact version with your printed serial. I too have had to procure new keys for win8 machines (did two last week that wouldn't recognize the keys on my machine)
What you may of had issue with was your OEM license being activated too many times -- if that happens, the automatic online activation will not work. You must use the phone number to activate your license, and it will ask "how many computers is this license installed on"... of course you just give the answer "one" and it activates it with no problem.
Are you referring to all flavors(Home Basic/Home Premium/Pro/Ultimate) from one disk? Installing retail/OEM from one disk has never been the case in my experience, though I have limited experience with 'retail' installs. I joined TechNet ~6 years back to obtain ISOs to reload various x32/x64/Vista/7 installs, but none of the machines' OEM keys I tried would work with the TN ISO's. If I'm not mistaken, they were specifically 'retail' ISOs.
No, Home/Pro/Ultimate are separate disks -- but OEM/Retail are exactly the same thing. You have to phone in your activation however, since OEM keys usually do not automatically activate over the internet.
Vista and up, there is no such thing as an OEM ISO image. XP had that and it was a great pain for support...
If you mean OEM in the sense of the pre-installed image on your recovery partition... that's not an "OEM" install in the same sense as the XP disks were... that's a customized image either made by something like nLite or installed on a generic factory laptop, pre-loaded with garbage, ran sysprep (to genericsize it) and imaged to a file.
The recovery image/factory image does not use the license on the bottom of your laptop usually -- it uses a factory volume license key that is pre-activated on the image. However if you try to recover that key with some key extractor, and use it to activate another installation from an official ISO, it will not work -- ie. that license will only activate at the factory. If you use the license from the bottom of your laptop, you need a genuine microsoft iso.
So long as you have a Windows 7 Pro license key on the bottom of your laptop, and use a Windows 7 Pro ISO, it will work.. or Home and Home, etc...
And... you appear to be absolutely correct.
"Vista and up, there is no such thing as an OEM ISO image. XP had that and it was a great pain for support..."
I was not aware OEM & RETAIL installation media were merged, cannot locate any search results verifying this, but I cannot find any recent issues being discussed either. Site where I buy software still has the categories distinguished & separate, but I never considered the media became one and the same w/ only distinction being the key itself(and all rights afforded Retail over OEM). I had numerous problems installing 7 when it appeared on consumer devices before I did any machine builds w/ 7(and made images of installation media that came with their licenses), hence my subscribing to TechNet(R.I.P.) before Digital River links became ubiquitous... and yeah, I have a dozen+ variants of XP due both to it's OEM/RETAIL duality plus the never-ending sfc /scannow prompt: "please insert original installation media" if XP received any Service Packs since original installation.
I do now recall unlocking Vista & 7 disks to install any flavor now that you mention nLight... another contributor to my lapse. Plus, I did find official MS pages that support your last point on unique disks for each flavor... I thought it was just for Enterprise.
EDIT:
"You have to phone in your activation however, since OEM keys usually do not automatically activate over the internet."
After activation failure, you can opt to insert a different key & retype the same key a 2nd time for online activation. That always irked me, I thought it was a bug.
Typically the "OEM" purchase of the ISO Disk comes in just a plain white envelope (with COA sticker somewhere on it) and "no official microsoft support" since it's intended for "systems builders" who microsoft expects to have their own support for consumers. A lot of people who build their own rigs choose this option because the "OEM" package is usually $10-$30 cheaper. The "Retail" packaging just comes with the fancy case with color inserts, etc... and "official microsft support".
If you are building your own rig, you're probably unlikely to call Microsoft for anything. If you are some company's internal-IT, you're unlikely to call Microsoft for anything.... Heck, if you are installing your own Windows installation, you're unlikely to call Microsoft for anything... So i just always buy the "OEM" packaging when I need a new license.
So the difference there is really just the packaging the ISO/Disk comes in and whether or not it has "official" support by Microsoft. Otherwise the ISO image on the disk is identical. :)
https://www.thurrott.com/uncategorized/1146/clean-pc-walkthr...
The, it didn't effect me because I reformatted is kind of a "First they came for the communists..." argument.
Oh and that I run a website over https matters too. I want that all users have the same expectation what that means.
I get it if I'm wiping out and putting on Linux or something, but that always seems like I'm wasting something I've already bought.
So, that communication your girlfriend might send you over https is not private any longer.
Go figure.
Never purchased a Lenovo but I was bent on using one for my next machine. No longer. Their lies about it "not being a risk" have put the affected customers at immense risk.
Just because others are doing it, does not make it right.
But what the fucking fuck have people not understood about this issue?
Someone might run open, free access points, sucking people in to connect and then they fucking MITM everything - inclusive that money transfer from your relative to you. How about that? Yes, you might be affected by this huge fuck up from Lenovo.
The HN crowd is such an insignificant percentage of the overall population that I don't see how word of mouth will have any impact.
You don't support lawsuits (all those pricks abusing the courts, extorting money from companies!)... right up until the hot second a company screws you, and then the courts are an appropriate recourse.
Maybe you could consider becoming a decent human being, learning some empathy, and realizing that perhaps other people have used the courts as recourse because they, too, were screwed by a company. Labeling lawsuits as an abuse of the court system or other laws is company defense 101.
It does not mean or imply "opposed" or "disdainful" or "disinterested", at all.
I'm giving Lenovo the benefit of the doubt here. Look at all the potentially malicious crap Dell, HP, Compaq, and others have installed on computers over the years.
Any experienced computer user should know and want to wipe the hard-drive and reinstall as soon as you get the computer, preferably from trusted sources, I'm not sure Microsoft's rules on customizing their reinstall disk. I wouldn't trust the reinstall partition either.
You have to also consider that the Chinese government might see all the news about NSA and US government hacking and intercepting hardware and they could require or secretly implement bugs into almost any Chinese made product, that's always been an unfortunate concern with Lenovo.
If Lenovo would push for more open standards of all computer components and have independent parties verify their internal processes, then that would go a long way to improving their credibility after this incident.
http://www.wired.com/2012/07/ff_kaspersky/all/
If this was going on with a US OEM, people would assume the NSA. But with Lenovo (which the US government refuses to buy btw) and Huwai and other non-vendors for the USG, HN'ers have regularly defended them and claimed the US was being paranoid or protectionist. How the hell do you think a fucking MITM gets onto a production image? This is financial suicide for Lenovo and they know it. This has all the telltale signs of government collusion. The CCP has a lot more to gain from stuff like this than Lenovo has to lose. How many people have been compromised from ship date until the day this gets uninstalled? Millions? For how many months? Years? That's a lot of SSL sniffing available to the CCP.
Why would you jump to that conclusion? Apple is just a company... and through the right view-port, even something like this can appear to be "consumer oriented" to management ("we're helping customers locate products and services easier").
Recently Canonical thought it was a great idea to bake-in Amazon ads into their search lens... so ads and product placement tagged with their affiliate link were baked into your OS.
No company is immune to doing stupid things, even Apple.
Apple have also made tons of mistakes when it comes to security and privacy.
But I still have a hard time seeing Apple ever intentionally adding a feature that proxies all a user's encrypted connections to inspect the content and insert ads.
Tim Cook's recent speech at the Cybersecurity summit sounded pretty earnest to me https://www.youtube.com/watch?v=QI6DvV2muDE
I can believe that management at Lenovo simply can't understand how serious this incident is - they're unlikely to have the technical knowledge needed to understand how severe the security problem is. I'm sure there are hundreds of Lenovo engineers tearing their hair out in frustration right now. Not that this excuses the management - they should be listening to their engineers.
[1] http://www.engadget.com/2010/06/24/apple-responds-over-iphon...
I believe you are raising this point in good faith, but it verges on disingenuous to compare them.
The thrust of my argument was that most large companies are bad at communicating about technical problems because of the way the message gets filtered through management, PR, lawyers etc. It's probably fair to say that Apple hasn't ever done anything this bad - but it's also disingenuous to hold them up as an unfailing bastion of niceness and competence.
About the closest they've come to that was the "goto fail" bug from a year ago or so, and that gave every appearance of being a mistake, and Apple didn't try to claim that it wasn't a problem (although they were, as usual, pretty quiet about the exact nature of the problem).
Difference in kind. Massive, massive difference in kind.
That's not an excuse for this, but it smells like incompetence rather than deliberate malice (at least on Lenovo's part - Superfish/Komodia may be another story).
Case in point; Lenovo pitched this as a "way for our customers to find new products". This is not a problem most users have, which is why the starting point for customer-centric design should ALWAYS be user feedback. This can be collected any number of ways (focus groups, surveys, etc.) but if you ask leading questions, you're going to get the answers you wanted to hear.
I don't doubt that the people who put this product together thought that it was an enhancement to the user experience. The problem is that they didn't do the research prior to even developing the project. So the end result is a product that solves only one problem: how can Lenovo get in on some sweet advertising dollars?
Such as interoperability deficiencies, deleting competing apps from the store, etc.
Wake up.
But I've never heard about AV software itself being a vector. Where can I find out more?
This is why I'm willing to pay a bit more for things I rely upon and care about. If you were a climber, would you try to save a buck by using an off-brand, bargain rope?
And to that extent, just because you paid more for an aluminum case with exactly the same internal components doesn't somehow make it seriously better... Macbook Air's for example have notorious overheating issues that kill the laptop...
Wait, your IT department just frantically rolled out clean disk images to the whole org? That's a funny coincidence...
It's probable that their lawyers told them to make this claim to lessen their exposure to lawsuits. If they admitted any kind of problem they'd be in hot water, but now the burden is on anyone bringing a suit to prove them wrong.
The first thing we do, let's kill all the lawyers.
They are so big and bureaucratic, half the time they don't know who is working on what.
This behavior is still inexcusable.
Somebody should be fired for putting this garbage on computers to "enhance the users experience."