The Superfish Funder List
qntra.net
qntra.net
Publicly naming companies and executives associated with this horrendous breach of privacy and security should hopefully serve as a deterrent for VCs who are considering making a quick buck by funding companies that are fucking over non-tech literate consumers.
Shaming Lenovo or its partners can make a difference because people do have a choice here. There are many laptop vendors out there. And if "Vintage Investment Partners" becomes well enough known as something the public finds distasteful, it could conceivably cause other companies to shun them as well.
You know, at least until they change their name. Still, I'd argue that if people cared enough, this approach would work in non-monopolistic cases.
I live in the Midwest and thought the same thing. After some research, I found several smaller companies who offer high speed internet, including the local telecom company.
I guess it boils down to if you're willing to pay more or pay the same and get slightly slower speeds without having to deal with Comcast and their horrible customer service.
Or move. Sorry to sound like a Comcast apologist, but it annoys me when people claim that they’re being “forced” to do something when they aren’t explaining why the obvious alternatives are unacceptable. I mean, maybe you can’t move because of your job. Or maybe you can’t afford to move. Or you have to live where you do because of your health. Or you can’t leave the state for legal reasons.
(This post is not in any way intended to condone or support the actions of Comcast or that of any other ISP.)
Obviously, shaming only goes so far... but realistically speaking, besides boycotts and shaming, there really aren't many effective ways to register your disapproval towards privately owned companies.
We should be publicly shaming the politicians that let this (comcast) happen or worse, are a part of the scam.
I don't have a ton of love for Verizon, but certainly the lesser of two evils.
A product that injects ads in your web traffic is crapware, but the scandal here isn't that superfish was crapware, the scandal is the security hole it introduced, which compromised Lenovo users. Yes, we all hate crapware, but there's a big difference between bothering people with sneaky, unwanted, ads, and opening the doors for malicious parties to intercept their online banking credentials.
However, a SSL intercepting software does not need to expose such a security flaw. It was only Komodia's moronic implementation which did so. If instead of using a fixed private CA key, they had generated one on the fly when the software is run for the first time, users wouldn't have been exposed.
Regarding the VCs, I would give them the benefit of the doubt as well. What where they pitched? SuperFish was about shopping using image recognition. For all I know, they raised money on a pitch about offering a search service, and then ended up pivoting. I don't know for sure if that's the case, but it's possible, and the VCs should get a chance to tell their side of the story before being dragged in the mud.
It's kind of like a mob boss who says to his lieutenant, "Boy, it sure would be helpful to us if that grocery store burned down". How else were they supposed to monetize their tech? They did exactly what everyone else does and found a way to use it for advertising.
The nationality of Lenovo is relevant insofar as it affects the applicability of US law. IANAL so I can't say how relevant that fact is, but I suspect it complicates litigation..
Really? How is looking at public blockchain data at all similar to installing malware?
Deleted comment
1. Ask users about income sources and Bitcoin usage, even for low volumes far below legal requirements.
2. Monitor and analyze blockchain transactions for activity they disagree with and close accounts with BTC in these chains, with no prior notice and no evidence of wrongdoing.
When a company is more aggressive at removing users than Chase bank you know there is a problem.
Countries inculcate values, educate people on the public dime, support R&D, etc. People should be proud when those policies bear fruit. E.g. Sergei Brin's family emigrated to the U.S. when he was six, because of Soviet discrimination against Jews. E.g. they were graded harder on university entrance exams, or given tougher exams altogether. He went to public high school and college, and went to graduate school at Stanford on a National Science Foundation fellowship. And Stanford, as an institution, heavily benefits from public spending on research.
So why shouldn't Americans take a little credit for Brin's success?
You would have no trouble sketching a ranked list of countries more and less likely to produce Google. You would be shocked to see Google emerge from Burma. You would be surprised to see the world's powerhouse search engine emerge from Greece, Spain, or Italy. Even among the top-tier countries, if you had to put money on it, you'd need an extremely good payoff to bet on anyone but the US.
If the US has "overwhelmingly nothing to do" with the success of Google, you have to believe Brin could have moved to Greece, or even Burma, and successfully built that company. Most of us probably don't even believe he could have succeeded in Germany, or the Netherlands.
Even if you stipulate away all the extrinsic network-effects stuff --- ie, stipulate he'd have gotten funded despite parking his company in Greece --- you would not place the same bet for his hypothetical attempt to buid Google in Greece.
"So why shouldn't Americans take a little credit for Brin's success?"
I'm not saying that living in America had nothing to do with it, it obviously did. I'm saying that the overwhelming majority of Americans had nothing to do with it, ergo being proud to be American is, in general, about as warranted as being proud that your favorite team won a tournament.
If you're a founding father, fought in the revolutionary war, influenced legislation in a historically significant ways, or did something of the sort, you may have a claim to be "proud", otherwise, you're a spectator, just like most people.
I think there's an element of the narrative fallacy implicated in the idea that the historical figures have a cause to be proud of American achievements, but ordinary people don't. Ordinary people are instrumental in everything achieved by those historical figures. The contributions of historical figures are immediately available to our consideration, because our stories revolve around them. Availability is usually a pernicious bias rather than a helpful signal.
later: it's also worth considering whether the fallacy might be in our concept of "pride", and who "deserves" "pride". There are practical reasons to attribute American successes to America; it reinforces them, motivates us to continue doing what works. There are fewer practical reasons to accord accolades to historical figures.
At the end of the day, either you've had a measurable contribution to something of value, and you can be proud of that, or you didn't, and you don't get to be proud just because people who have a similar passport to yours have.
Unless they are your children and you brought them up. Then there's some justification in your feelings.
Spin your mistakes however you want in a press release, but don't lie about security vulnerabilities that put users at risk.
Superfish is profiting, they're being held accountable for their actions. Lenovo is responsible, they are being shamed duly.
The same happens with, for example, gun manufacturers and other war profiteers.
I'm not trying to pick a side here, just pointing out: blame doesn't need to fall on just one party. They are partners in crime.
that has nothing to do with anything.
>should we really be blaming superfish? this company makes software, seams like a bunch of hackers to me.
More like a bunch of crackers. They produced a nefarious piece of software (which couldn't be used responsibly or in a just way), and it got used in a way that harmed users. Both parties profitted from hostile actions, which then hindered the defense of their userbase.
"Should be we really be blaming Cult of the Dead Cow? This company makes software, seems like a bunch of hackers to me. The users of BackOrifice are the real culprit here."
(yes, I know, my cyber-threat definition list is frightfully out of date. Maybe I just like cDc)
That doesn't mean they aren't responsible and shouldn't burn their fingers; investors actually should look into these things when they decide where to invest.
Ultimately its worth remembering this is Windows..... Microsoft has to be responsible for the crapware installed when people buy a Windows computer. The reasonable conclusion is that if you buy Windows you risk stuff like this because Windows resellers install crapware on top of clean Windows builds.
We use to ship them our consumer laptops for testing, and the result was always the same "get rid of the crapware". MS is probably more upset about this than anyone, because ultimately this isn't about Windows at all, but people don't differentiate between Windows and the garbage that OEM's throw on their boxes, so they get blamed as well.
Ultimately, Lenovo should take the full blame for this.
edit: grammar
Linus is the maintainer of the Linux kernel. Linux is a product of the work of many people.
Linux is free, and can be redistributed without securing licensing or rights to do so.
Microsoft Windows is a proprietary product, which many people are only exposed to from the initial install on their bought hardware. The company who supplies the hardware, along with the company that supplies the software engage in contractual deals to allow this to happen.
Microsoft's image benefits when it is known that they do due-dilligence in checking out the suppliers who they allow to represent their product through licensing.
How are you okay with companies who create malware for corporations for pay? They deserve no responsibility themselves for simply existing with nefarious motivations? Microsoft requires licensing their product to use it, and goes an extra step by providing evaluation of the products which use their licensed software, and are vocally against the addition of crapware; but they take no blame when they allow their product to be continually licensed by a vendor that does harm to the image?
To answer your question: The distribution that is responsible for spreading the adware should be held responsible, as should the developers of that adware. That's likely why Mint became so popular (numbers wise) after all the Ubuntu fiascos in semi-recent history.
I don't think it's as simple as a one-party fault. Sorry.
Windows is not free.
When an OEM licenses Windows for resale in their PCs, that comes with certain terms and conditions about what the OEM can install. If this falls within the terms of the agreement of what the OEM can do, then Microsoft needs to take at least some of the heat.