I'd say that someone having cracked out the password for the private key is a bit more than a 'theoretical' concern. This might be the most tone-deaf handling of a potential PR disaster so far this year.
I'd say that someone having cracked out the password for the private key is a bit more than a 'theoretical' concern. This might be the most tone-deaf handling of a potential PR disaster so far this year.
It's appealing to a common and sucessful strategy of dismissing the concerns of experts as the irrelevant waffling of a bunch of eggheads disconnected from reality. Lenovo are hoping their user base will pop "security researchers" in the same bucket as beachfront property owning SUV drivers place "climate scientists".
Such a pity, I was looking forward to getting an X1...
It's like the opposite of damage control.
Courts of law have a good reason to hold high standards of evidence. For everyone else it's just an excuse for laziness. Not that I'm any better, I just don't insist on rationalizing it :-)
I agree that it's trivial to exploit, but I choose to believe that, in the general case, people/entities are lazier than they are evil. That said, laziness can be in the form of "not taking into account the externalities", which can be indistinguishable from actual malice (which I define as knowingly and/or willfully causing harm).
I still think Lenovo's behaviour in this case is that form of laziness, though my comment above means I'm on the fence.
FWIW, I agree with you: I put thoughtlessness and callousness fall under the laziness umbrella.
Then again, I may be underestimating management's ability to drink their own kool-aid.
Given the general sliminess in computer, phone and software companies, there is no "pure" option except to buy some ancient computer and never use it on the internet, like RMS. This isn't acceptable to me. I will buy what serves my own needs, and you can do whatever you want.
I've been eyeing Macbooks forever, but as far as I know Linux support has never been great, despite the prevalence of their hardware. System76 sells some good Linux-oriented laptops. Some of Dell's laptops are Ubuntu-certified. I had a good HP Elitebook via work about 6 years ago, but everything I've tried of theirs over the past couple years has been throw-out-the-window bad.
I ask that from a Lenovo Thinkpad T520i, one of a half-dozen or more I've owned or used over 15+ years, and absolutely my preferred mobile hardware over that period.
I think you're assuming that the broader public shares the indignation of HN about this. On mainstream news sites, it's down under the 'technology' heading. It sounds like Lenovo is scrambling a fix that will remove the certificate. If that's out in the next day or two and they have a way to get most affected users to apply it, probably hardly anyone will get clearly 'hacked'. They'll keep playing the 'honest mistake' card, and it will mostly blow over.
In a couple of days, they might be much more contrite about this. But today, the PR department's number one job is to keep it from becoming a big story in mainstream media.
You say you do due diligence to make sure the software you include is secure... yet you miss on such blatant vulnerabilities.
"Not doing enough" only scrapes the surface.