The latest version of Windows Defender is actively removing the Superfish software and the cert.
The text of the definition is here: http://pastebin.com/raw.php?i=us7iXvkn
The latest version of Windows Defender is actively removing the Superfish software and the cert.
The text of the definition is here: http://pastebin.com/raw.php?i=us7iXvkn
Even if 'average people' have no idea what a certificate is or why it's important, those who do have an outsized influence on PC purchasing, and are likely to remember this for years.
It's quite a convincing product, quickly becoming an integral part of the OS. And rightfully so.
Not really. Microsoft, itself, actually suggests that you use a third-party antimalware product.
It scores pretty low on AV-Test.org[1] too, but it's better than nothing.
[1]: http://www.av-test.org/en/antivirus/home-windows/windows-8/
Its brand is as tarnished (if not more so) by this sort of crap.
Not that Microsoft's own hands are clean or that the issue of crapware preloads isn't a massive problem.
Google should also be paying attention: Android preloads are also increasingly a massive turn-off.
ArsTechnica covered this issue in their reporting today http://arstechnica.com/security/2015/02/windows-defender-now...
I'm generally in favor of MS doing this specific thing, but there is potential for abuse here.
I think Microsoft went from being a hated software giant to sort of an underdog vis-a-vis Google, Facebook, Amazon and Apple.
They are very big and strong no doubt, but I think the attitude they are projecting since switching CEO recently, their open source efforts, and such make them look pretty good PR-wise among the tech crowd.
Though I believe virtually all preloads were OEM actions, not Microsoft's directly.
Hell of a name, you've got to admit.
Bruce Schneier's discussion at the time:
http://web.archive.org/web/20011005071623/http://www.counter...
One of his speculations:
it is actually an NSA key. If the NSA is going to use Microsoft products for classified traffic, they're going to install their own cryptography. They're not going to want to show it to anyone, not even Microsoft. They are going to want to sign their own modules. So the backup key could also be an NSA internal key, so that they could install strong cryptography on Microsoft products for their own internal use.
Though given alternative methods of bypassing any Microsoft security, not really necessary.
The rest is simply PR, microsoft is still the evil corp it used to be but has to fight other evil corps to keep a share of a market it once dominated. Microsoft had too much money to burn to die quickly, its agony will take quite some time.
I don't buy it. I think Microsoft seems to have actually made real changes. If you want an example of what a giant evil tech corporation dying slowly looks like, take a look at Oracle. Their core business is basically obsolete, but they'll go on killing open-source projects and squeezing their locked-in enterprise customers for many years.
Microsoft is in a hard place in terms of determining what is or isn't allowed on their systems (due in large part to their own past and quite probably ongoing monopoly abuses), but fixing obvious flaws is to be applauded.
I don't champion the company often, but they're doing the right thing here. Actually, sanctioning Lenovo for letting this happen might be another option they've got. Though something tells me they won't play that card (and quite possibly cannot).