Lenovo CTO: We’re Working to Wipe Superfish App Off of PCs
blogs.wsj.com
blogs.wsj.com
I'd say that someone having cracked out the password for the private key is a bit more than a 'theoretical' concern. This might be the most tone-deaf handling of a potential PR disaster so far this year.
It's appealing to a common and sucessful strategy of dismissing the concerns of experts as the irrelevant waffling of a bunch of eggheads disconnected from reality. Lenovo are hoping their user base will pop "security researchers" in the same bucket as beachfront property owning SUV drivers place "climate scientists".
Such a pity, I was looking forward to getting an X1...
Courts of law have a good reason to hold high standards of evidence. For everyone else it's just an excuse for laziness. Not that I'm any better, I just don't insist on rationalizing it :-)
I agree that it's trivial to exploit, but I choose to believe that, in the general case, people/entities are lazier than they are evil. That said, laziness can be in the form of "not taking into account the externalities", which can be indistinguishable from actual malice (which I define as knowingly and/or willfully causing harm).
I still think Lenovo's behaviour in this case is that form of laziness, though my comment above means I'm on the fence.
Then again, I may be underestimating management's ability to drink their own kool-aid.
FWIW, I agree with you: I put thoughtlessness and callousness fall under the laziness umbrella.
Given the general sliminess in computer, phone and software companies, there is no "pure" option except to buy some ancient computer and never use it on the internet, like RMS. This isn't acceptable to me. I will buy what serves my own needs, and you can do whatever you want.
I ask that from a Lenovo Thinkpad T520i, one of a half-dozen or more I've owned or used over 15+ years, and absolutely my preferred mobile hardware over that period.
I've been eyeing Macbooks forever, but as far as I know Linux support has never been great, despite the prevalence of their hardware. System76 sells some good Linux-oriented laptops. Some of Dell's laptops are Ubuntu-certified. I had a good HP Elitebook via work about 6 years ago, but everything I've tried of theirs over the past couple years has been throw-out-the-window bad.
It's like the opposite of damage control.
I think you're assuming that the broader public shares the indignation of HN about this. On mainstream news sites, it's down under the 'technology' heading. It sounds like Lenovo is scrambling a fix that will remove the certificate. If that's out in the next day or two and they have a way to get most affected users to apply it, probably hardly anyone will get clearly 'hacked'. They'll keep playing the 'honest mistake' card, and it will mostly blow over.
In a couple of days, they might be much more contrite about this. But today, the PR department's number one job is to keep it from becoming a big story in mainstream media.
You say you do due diligence to make sure the software you include is secure... yet you miss on such blatant vulnerabilities.
"Not doing enough" only scrapes the surface.
"It is very important to delete the certificate even though the application itself has been removed."
http://forums.lenovo.com/t5/Lenovo-P-Y-and-Z-series/Removal-...
Didn't seem that important earlier today: https://web.archive.org/web/20150219151726/http://forums.len...
"files in user directory will stay intact for the privacy reason. Registry entry and root certificate will remain as well. "
http://marcrogers.org/2015/02/19/will-the-madness-never-end-...
LOL. Yes sir! The internet is filled with people happy about bloatware...
I seriously wonder how much money they make off these bloatware providers to risk pissing off customers and devalue their brand.
It can't be that much can it?
The only thing that will change going forward is they're going to do more due diligence on their AdWare suppliers before agreeing to the deal.
Here is something to start with: "if you offer a product A bundled with product B you have to offer A alone for the price not more than A bundled with B"
while weak and not really addressing many issues with bundling it at least gets rid of the most blatant problem of malicious add-ons.
Then something like A for not more than price(A) + 1/2price(B) and now we are getting rid of a lot more useless stuff.
It might now be the case going forward that Lenovo will be a better choice. They've been burned.
The shovelware that most vendors ship on their boxes is offensive, yes. It's annoying. It steals a little of my life each time I buy a new machine, because I have to take time to re-image the system or clean off the crap (my current HP Envy was particularly egregious in this waste of my time, in that the restore image didn't work, so I had to wait ten days to get a restore DVD from them, and had to pay them $15 for the privilege of being able to restore my system). But, none of this is comparable to installing spyware on your customers systems.
They keep making claims that it isn't spyware, but in a previous HN thread, someone was trivially able to find the tracking and re-targeting codes in the injected code. It is the definition of spyware, and even worse, it is broken in such a way that it enabled MITM attacks.
"It might now be the case going forward that Lenovo will be a better choice. They've been burned."
Have you read their statements about it? Every single one of them denies any wrongdoing. They believe it's just a "customers don't like this software" issue. They don't believe it is a "We have likely committed crimes against our customers", which is what it actually is, at least in jurisdictions that take citizen privacy at all seriously. (In the US the TOS click through probably protects them, because the US doesn't give a shit about privacy, but in some other countries it probably wouldn't.)
Of course. You make out like that's a significant detail. "Large company denies liability" is not a headline. Do you honestly think Dell, HP, or even Apple would say anything differently in a similar situation?
Based on the quantity and quality of the software pre-installed on every laptop I've ever owned, I'm not quite as convinced as you are that this is exclusively an issue that could only ever happen to Lenovo customers.
I'm saying I would need to see a "mea culpa" from Lenovo before I would even begin to think about trusting them.
Instead, given the general attitude of most PC manufacturers with regard to what is pre-installed, I don't think boycotting Lenovo would necessarily save you from this sort of issue in the future. You're just as likely to be burned by almost any one of them. This product wasn't even made specifically for Lenovo.
Perhaps this attention will make Lenovo more careful in the future. It equally might not. It might make other manufactures more careful. Or it might make no difference at all.
Now waiting for the new Dell XPS13? Or anyone has another option for a powerful ultrabook that goes well with the pinguin?
Am I the only one who thinks they deserve a little credit for getting their CTO to publicly deal with the issue on the same day all this came to a head, including saying that a guy was literally sat coding out a removal tool right now and due for release tonight? That's a damn respectable feedback loop for a megacorp if you ask me, and we'd have a lot less to whine about here on HN if all mistakes were rectified so expeditiously.
And yes, while I'm running my own installation of Debian GNU/Linux, I preserved the Windows installation for (very) occasional use. Only under a VM, and not in two or more years that I recall. With this news I'm strongly inclined to wipe it
But pulling crap like this is a tremendous erosion of trust. In your products. In any Microsoft Windows installation (not that I trust these in any event). It's a tremendous hit to your own brand equity, as well as Microsoft's.
The sad truth is that there are few alternatives out there, and that there are plenty of other security risks. But you can solidly bet that as a consumer and IT director I'll explore the hell out of other alternatives before making my own or corporate purchases and/or recommendations.
>>Lenovo Y50, Z40, Z50, G50 and Yoga 2 Pro models.
Above is announced from some sources and
>>Lenovo-branded devices sold between September 2014 and January 2015 through consumer online and retail stores, like Best Buy and Amazon.com, are likely affected by the Superfish adware
Has anyone got any additional info?
But they are trying that through the signature store.
Another person had discovered a method to automatically disable Superfish by placing a special <meta> tag on your page; within two hours of posting his discovery, Lenovo silently removed the disable ability: https://news.ycombinator.com/item?id=9076788
Deliberately preventing people from disabling Superfish doesn't seem like something a company "working to wipe Superfish app off of PCs" would do.
I don't believe a single word uttered by these snakes.
These are the URLs on the malware peddler's server I examined to get an idea for how to detect whether their malicious payload injection has taken place:
https://www.best-deals-products.com/ws/sf_code.jsp
https://www.best-deals-products.com/ws/sf_preloader.jsp
https://www.best-deals-products.com/ws/sf_main.jsp?dlsource=...