Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless
wired.com
wired.com
The latest version of Windows Defender is actively removing the Superfish software and the cert.
The text of the definition is here: http://pastebin.com/raw.php?i=us7iXvkn
I'm generally in favor of MS doing this specific thing, but there is potential for abuse here.
I think Microsoft went from being a hated software giant to sort of an underdog vis-a-vis Google, Facebook, Amazon and Apple.
They are very big and strong no doubt, but I think the attitude they are projecting since switching CEO recently, their open source efforts, and such make them look pretty good PR-wise among the tech crowd.
Though I believe virtually all preloads were OEM actions, not Microsoft's directly.
Hell of a name, you've got to admit.
Bruce Schneier's discussion at the time:
http://web.archive.org/web/20011005071623/http://www.counter...
One of his speculations:
it is actually an NSA key. If the NSA is going to use Microsoft products for classified traffic, they're going to install their own cryptography. They're not going to want to show it to anyone, not even Microsoft. They are going to want to sign their own modules. So the backup key could also be an NSA internal key, so that they could install strong cryptography on Microsoft products for their own internal use.
Though given alternative methods of bypassing any Microsoft security, not really necessary.
The rest is simply PR, microsoft is still the evil corp it used to be but has to fight other evil corps to keep a share of a market it once dominated. Microsoft had too much money to burn to die quickly, its agony will take quite some time.
I don't buy it. I think Microsoft seems to have actually made real changes. If you want an example of what a giant evil tech corporation dying slowly looks like, take a look at Oracle. Their core business is basically obsolete, but they'll go on killing open-source projects and squeezing their locked-in enterprise customers for many years.
Microsoft is in a hard place in terms of determining what is or isn't allowed on their systems (due in large part to their own past and quite probably ongoing monopoly abuses), but fixing obvious flaws is to be applauded.
I don't champion the company often, but they're doing the right thing here. Actually, sanctioning Lenovo for letting this happen might be another option they've got. Though something tells me they won't play that card (and quite possibly cannot).
It's quite a convincing product, quickly becoming an integral part of the OS. And rightfully so.
Not really. Microsoft, itself, actually suggests that you use a third-party antimalware product.
It scores pretty low on AV-Test.org[1] too, but it's better than nothing.
[1]: http://www.av-test.org/en/antivirus/home-windows/windows-8/
ArsTechnica covered this issue in their reporting today http://arstechnica.com/security/2015/02/windows-defender-now...
Even if 'average people' have no idea what a certificate is or why it's important, those who do have an outsized influence on PC purchasing, and are likely to remember this for years.
Its brand is as tarnished (if not more so) by this sort of crap.
Not that Microsoft's own hands are clean or that the issue of crapware preloads isn't a massive problem.
Google should also be paying attention: Android preloads are also increasingly a massive turn-off.
[1] Edit: Draper Fisher Jurvetson, the $4 billion Menlo Park VC firm that backed Baidu, Hotmail, Tesla, SpaceX and Twitter.
https://www.crunchbase.com/organization/superfish
links to their website, which links to
"But Superfish tells us it stands by Lenovo’s assessment. “Superfish is completely transparent in what our software does and at no time were consumers vulnerable—we stand by this today.” a company spokeswoman said. “Lenovo will be releasing a statement later today with all of the specifics that clarify that there has been no wrong doing on our end.”
Now that an official CERT announcement has been released:
https://www.us-cert.gov/ncas/alerts/TA15-051A
I think their misleading comments are going to come back and bite them more than they have already.
[EDIT - Looks like they are back peddling a little on: http://news.lenovo.com/article_display.cfm?article_id=1929
" Finally, we are working directly with Superfish and with other industry partners to ensure we address any possible security issues now and in the future. "
" By the end of this month, we will announce a plan to help lead Lenovo and our industry forward with deeper knowledge, more understanding and even greater focus on issues surrounding adware, pre-installs and security. We are eager to be held accountable for our products, your experience and the results of this new effort"
And on: http://support.lenovo.com/us/en/product_security/superfish
"Vulnerabilities have been identified with the software, which include installation of a self-signed root certificate in the local trusted CA store. ... Superfish intercept HTTP(S) traffic using a self-signed root certificate. This is stored in the local certificate store and provides a security concern. "
]
Just because I've been seeing this mistake a lot lately: peddling is selling. Pedaling is the thing you do with your feet.
(Edit: Obviously this is not representative of the general population, and I didn't mean to suggest it was. I was just noting that my efforts to warn people about the untrustworthiness of Lenovo were thwarted because none of them trusted Lenovo to begin with, not for software at least, and that seemed interesting.)
Fortunately Lenovo do have a system updater that does a fantastic job on driver downloads etc.
Also, when the SSD in my Macbook Air failed, I was able to netboot their internet recovery thing, which let me install OS X on a USB3 hard drive. Pretty cool.
I see. They have that stuck into Disk Utility now. One point to Apple.
Disk Utility is a bit kludgy nowadays, though, and it seems they're not doing as good a job as MS publicizing the tool. (Too small a sample size here, but I ran across the MS tool by accident while searching/browsing. With Apple, a human had to tell me.)
1) Boot into Recovery mode (Cmd + R), then use Internet Recovery [1] to install OS X. This works even if your HDD or SSD is completely blank. All Macs from around mid-2010 onwards are supported. [2]
2) Download the latest OS X installer from the Mac App Store, then either use the bundled 'createinstallmedia' command-line app to create a bootable USB flash drive [2] or a third-party app called DiskMaker X [3].
[1] http://support.apple.com/en-gb/HT4718
[2] http://support.apple.com/en-gb/HT202313
Note: I do own Windows 8.1 Pro, so don't think this is based on my experience pirating the software. I merely have examined the licensing system for some software I was writing.
I haven't seen any recent statistics, but at one point, 74% of rootkit infections were on pirated copies of Windows XP [0]
[0] http://www.zdnet.com/article/study-rootkits-target-pirated-c...
According to Microsoft[1], 32% of pirated Windows 7 copies and activation cracks resulted in some sort of malware infection
Speaking anecdotally, most of the friends and family whose computers I've had to clean up have been running some sort of cracked/pirated software that they'd downloaded or had been given to them by a friend
[0] http://voices.washingtonpost.com/securityfix/2009/05/pirated...
[1] Admittedly, Microsoft has somewhat of a bias, but the number sounds reasonable to me: http://archive.news.softpedia.com/news/32-of-Pirated-Windows...
http://windows.microsoft.com/en-CA/windows-8/create-reset-re...
Got me a 8.1 ISO, installed with a volume key.
Even if it currently does not do that, I just don't trust it to not do that in general.
It does not let you install or update the crapware that comes with systems. It is actually quite difficult to get that stuff other than saving it when you get a new system. BTW IBM/Lenovo have historically had way less crapware than other vendors. I think Lenovo got complacent in this case, hearing "you guys do less crapware than the others" and confusing it with "you are doing a perfect job". Less worse is not the same as doing good.
Someone's useful add-on is someone else's garbage. They have some software called Access Connections which provides more gui and control over networking, such as which access points to connect to based on location profiles and who knows what else. I don't want that since I mostly use Linux, and Windows does a good enough job when I am using it. The system updater has never installed it, nor tricked me in any way.
So if Lenovo was evil, they can just ship shit in their drivers, get it certified by MS, and have it distributed automatically by Windows Update driver install.
It's why I've, in general, never trusted them.
But now that I know that Lenovo is a piece of shit company with zero integrity, I don't even want to trust their hardware.
But what am I gonna do? There's essentially no options to replace an old X-style ThinkPad. The newest Carbon X1 is as close as anything. Everyone else is moving to the Apple-style clickpad, which is unacceptable. HP and Dell sell mostly crap. Apple's devices are hot and unergonomic (apart from questionable Windows driver support).
So good luck not trusting them. And I doubt HP'd do any better.
My wild guess would be they got in the ballpark of $0.25 an install.
Hint: It starts with $ and ends with $.
I do not object to this notion at all! For one thing, it's not my comparison, it's my co-worker's. Also, an "inversion" of the scale's sign would serve as a sharp and salient commentary on problems in our society.
The road to poor security is paved with indifference.
Hey Lenovo, can you install this root cert I made on your entire product line for me? I'll give you like $20 for it. It's at least better than Superfish - I promise not to include the private key with a trivially-crackable password in the install, so only I can intercept all secure communications by any of your customers, instead of anybody in the world.
They sell laptops. It's not a free service, I am the customer not the product. Did Lenovo have a pressing financial need for these extra pennies on the side? Really? How is that benefit vs risk calculation looking now?
They should just admit the problem, thank the security experts, and develop an easy fix.
> We're sorry. We messed up. We're owning it. And we're making sure it never happens again. Fully uninstall Superfish: http://lnv.gy/182BW8g
And most of all it helped if there would be litigation. The thought goes if CTO goes on record admitting guilt that is a slam dunk case for anyone suing them.
Therefore the typical corporate non-apology apology "I am very sorry you feel this way" kind of bullshit.
The problem of course is information sources are a lot more diversified, with Twitter and other media bubbling up tech news to the top faster.
The other problem they are facing is a lot of technical people were their proponents and would advocate and drive purchasing decision (in turn putting their own reputation on the line). This is where it is going to hurt them.
Something to the effect of "We are very sorry, this was a mistake, here is how to remove the software, we'll send you free software or Lenovo.com discounts. We'll cut off our relationship with this company. Etc, etc.." I think would have been much better for them in the long run.
“We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns.”
A good general guideline when buying an off-shelf Windows machine is to do a full wipe first. There may be some manufacturers who are immune to this, but assume everyone's included some bloatware. I find too many people who buy Windows machines start by attempting to manually remove this stuff, which is often a hopeless proposition. Clean wipe, reinstallation.
This isn't the reason why most startups/devs have moved to Apple, but it sure helps.
We programmers should use this as an analogy for dealing with everyday psychological issues.
If we assume firmware is safe, wipe it and do a clean install from trusted media.
[1] http://www.phoronix.com/scan.php?page=news_item&px=Coreboot-...
Now the question is of course what else are they installing and what other yet undiscovered issues we'll find. It sounds like FUD but so far based on their response, they seem either incompetent (stupid) or malicious. And I don't exactly like either...
I'm really interested if a high end (but "consumer") ThinkPad like http://www.microsoftstore.com/store/msusa/en_US/pdp/Lenovo-T... that you can buy at a retail store (in this case, a special MSFT Store version that has plain Windows supposedly on it) was infected.
It didn't have bloatware crap installed (as say US govt or big companies would not like that). It came with a smart card reader and such. Had a fingerprint scanner (back when there were not common).
Initially also they didn't have all these "consumer" models (Y,G,W,...).
A few months ago there was a HN story about a car manufacturer who had made the decision to use cheaper parts for the ignition. They had the critical internal reports from engineers, and when the deaths started to pile up they did the same thing as lenovo. Act clueless, downplay the issue, make a fix, and silently move on. So long it just customer outrage, it is perfectly fine to do borderline illegal things in order to raise some revenue.
Here is such a page:
https://badfish.filippo.io/yes.png
That's an image of the word "Yes" signed with the Superfish certificate. If your browser shows that image without warnings about an invalid cert, the backdoor exists.
Here's how this type of MITM attack works.
Situation: user is using laptop in public location with WiFi. Between WiFi device and net is a computer with MITM software.
Client laptop requests "https://www.bigbank.com". MITM box gets HTTPS request, sees it is for "bigbank.com", and generates a fake cert for that site. It then uses the Superfish root cert to sign the fake cert. MITM box acts as server for that connection and sees the user's traffic in the clear, unencrypted. The Lenovo client laptop sees a valid cert chain descending from the Superfish cert installed by Lenovo. The user sees a green bar and lock icon.
MITM box then opens an HTTPS connection to "https://www.bigbank.com", and acts as client for that connection. The two connections are connected together as a proxy, so that the user sees what looks like a valid HTTPS connection. The MITM box can log everything, including bank passwords.
There's even open source software for doing MITM attacks: https://code.google.com/p/subterfuge/
It's not we haven't thought about replacing management with shell scripts...
(komodia is apparently the underlying tech for the superfish thingy)
Why buy a laptop from a company that has ties to the Chinese government [2], an authoritarian government that supports dictators in Africa and totalitarian government in Russia, oppressing women and children in those countries?
[1] http://www.theverge.com/2013/7/30/4570780/lenovo-reportedly-... [2] http://en.wikipedia.org/wiki/Lenovo
I guess because they make good hardware.
2.) How is US government authoritarian? Have you actually lived in a country that has no elected representative?
But Lenovo isn't owned by the Chinese government, either.
> 2.) How is US government authoritarian? Have you actually lived in a country that has no elected representative?
The existence of more dictatorial countries doesn't mean the US isn't authoritarian—it is a spectrum rather than a dichotomy.
> Favourable to or characterized by obedience to authority as opposed to personal liberty; strict, dictatorial.
It's certainly reasonable to argue about whether this actually applies; but I don't think that it represents a useless dilution of the word to think that it might. (Well, not 'dictatorial', but the rest of it.)
> It's certainly reasonable to argue about whether this actually applies
literally that it is reasonable to argue, i.e., that neither position is obviously irrefutably true; and also I think I've created enough of a de-rail already here; but, if I had to make an argument for authoritarianism, I think that I would claim that the concept of free-speech zones instantly implies, for some parts of US government at some times, more respect for authority than personal liberty.
2.) In the way that a company can be compelled to comply with an order from the government, including the requirement that the company may not disclose to anyone the nature of that order or the gag order, and that there is effectively no way to challenge such orders in a court of law.
>Have you actually lived in a country that has no elected representative?
Yes. What difference is that supposed to make?
"Don't blame me - I voted for Kodos." - Homer J. Simpson.
Now I ended up buying a cheap ASUS Chromebook for traveling, replaced drive with a large one and installed Ubuntu. But still haven't decided if I want to replace my main machine.
Was eyeing Carbon X1 models for a while, but now will have to rethink.
Besides, like some people here, I always wipe everyone out and reinstall my own distro on it (Ubuntu usually).
There is nothing connecting this to the Chinese government. This appears to be a a cross-border display of greed and incompetence.
So maybe Lenovo isn't the only offender.
Edit: Duh. It was snapfish, not superfish. I've been reading about superfish so much that's what I saw.
Before this adware-gate, EVERY PC manufacturer bundles adware, HP, Dell, Acer, Lenovo, Asus to name a few top players(Apple perhaps is the only exception as I don't count them as a PC manufacturer). Did anyone bother to look if there were tons of similar security risks with those?
Lenovo is a company that you paid your money to to buy a laptop. It shouldn't come pre-infected with something that compromises your security and privacy.
They screwed up by denying there was problem in the first place. Which means they were defending both their decision to install Superfish as well as, by proxy, Superfish itself.
Thus they are seen to be either incompetent (can't trust them) or malicious (also can't trust them).
Also consumers never bought Superfish. They paid for a relatively expensive piece of hardware from Lenovo and got screwed. They are right to blame Lenovo for it.
Because Lenova is the one who took your hundreds to thousand+ dollars and in return compromised your experience (for what has to be pennies). And in this case it caused a serious security compromise?
"EVERY PC manufacturer bundles adware"
Crapware/bloatware and adware are very different things. Dell installs some bloatware crap that I can uninstall (and even that is, truly, unacceptable. Again, they can't make more than a dollar or two on that junk, yet they compromise the user experience), but they don't MITM my secure communications, or compromise my security.
This has nothing to do with Lenova being a Chinese company. Further, no one expects anything out of Superfish (some slimy adware company), but they do expect standards from Lenova.