Class action lawsuit filed against Lenovo over Superfish
unitedstatescourts.org
unitedstatescourts.org
After a pro-forma hearing a judge will approve the settlement as fair, reasonable, and adequate.
There are basically no long term downsides to Lenovo for doing what they did.
We simply don't know the effect because we know no sale figures, or do we?
Though it's akin to avoiding Bank America Corp in practice, they have their hands in every pot.
The thing these companies miss is that non-tech people ask their tech friends/family before purchasing new things... So piss off a few 100,000 of the techy people and that can translate over the next few years to millions of lost sales.
With Mac's Spaces, I can switch to another screen running Windows with Control-Rightarrow (using a non-Mac keyboard here). It's really seemless and I've never found a single drawback to it.
If you're fine with your company's data possibly being compromised in the future then continue your ordering from Lenovo.
I will still buy from them because I always make it a habit to do a clean install whenever I get a new computer just because of all the crap every vendor adds to consumer PCs.
However I could be wrong, and perhaps there are companies that feel betrayed. Custom images may be a thing only large companies do.
As a consumer, I still view Lenovo as the best PC hardware and would buy again but would probably be suspicious of any new purchase (as in, wipe the HD and install a store-bought copy of Windows myself). That said, I use the Thinkpad line which was unaffected by Superfish from what I know.
Do you remember when Sony went after GeoHot, George Hotz, and fail0verflow for his and their reverse engineering of the PS3 and the outrage and virtual pitchforks that were raised with others touting that they too would never purchase a SCEA/SCEI product again?
Remember even more outrage that was raised after PSN went down and it was revealed just how incompetent their internal network security was and how they allegedly stored unencrypted user information and used significantly insecure and broken cryptographic hashing algorithms?
In both instances, people said that they were done with Sony. Yet, the Xbox One has had significantly less adoption than the Sony PS4. Please note, I'm not going to argue that the people that said that they were no longer purchasing Sony products are the very same people that bought a PS4 over an Xbox One, but I am arguing that these people had a minuscule to nonexistent effect on the overall repercussions against Sony as to not matter.
Searching for "Xbox One PS4 Sales" brings up hundreds of articles ranging from just after launch up to this very day with month-by-month numbers landing from a 1.4 million unit difference in January of 2014, to a 1.7 million difference between the PS4 and Xbox One in the second quarter of 2014, and estimates at that time of 9 million PS4s sold globally versus 5 million for the Xbox One. An article from October of 2014 pegs the PS4 at a 40% lead over the Xbox One. This is a significant difference. Apparently, no one else cares how draconian or insecure a company treats their data, because only a few people remember the short term disasters over the long term entertainment value they receive from the products produced by these companies.
Given the "currently playing" lists on e.g. Steam after a boycotted game releases? I'm going to make that argument. It seems most simply don't have the willpower to maintain a boycott until even, say, the first sale for a single game - nevermind a whole company long term. It's easily 90% noise. Talk is cheap.
> but I am arguing that these people had a minuscule to nonexistent effect on the overall repercussions against Sony as to not matter.
[citation needed]
While I'd be inclined to believe you're right based on the mentioned ancedata, that doesn't necessarily mean they'll have a minuscule effect on other companies, if consumers are ever sufficiently incensed enough to follow through on their word. Or avoid purchasing from them without making big fuss about it, as I'm currently doing with Lenovo for at least my next purchase.
I'd also note that laptops are a bit more "fungible" than consoles and gaming networks, in the sense that you can easily find similar laptops with similar specs for anything you might want from Lenovo's lineup. You'll hear gamers talk about how they "need" the latest COD, or a PS4, but they're more likely to pun about "Hell" (if only out of amusement) than talk about how they "need" another Dell. Or Lenovo. Better chance of making a difference?
...that said, I'm not seeing any kind of significant dip in Lenovo's stock price around the Superfish debacle. Superfish doesn't appear to be publicly traded, although their placeholdered homepage is a good sign for bad things having happened to them.
Still, it's better for this to be in the open, with all the bad PR associated to it, so that companies will think about it twice before pulling similar stunts in the future.
Is that how it will pan out though. I'd imagine it's more likely to be that Lenovo get away with paying a little of their profits out in the class action but still overall profit from the whole deal. Then companies will be encouraged to do so long as when they factor in the cost of the lawsuit they still come out on top.
IMO penalties should be such that a company doing this sort of thing makes no profit and is at a very real risk of having to be liquidated if they already weren't making a profit. For large companies the payout should be measured in $100 millions as that's the only sort of level of fine that will be noticed.
Directors in charge of that section that authorised or actioned the activity should be barred from being directors again and where appropriate face criminal charges. In Lenovos case if they can ever afford to do this again and if the controlling elements (or those who should have exercised control according to the org chart) aren't prosecuted under eg CFAA then the punishment will be too small.
The main point is that it makes a clear punishment for the company; so that others think before doing it themselves. If the cost of loosing the case is high enough, all manufacturers will learn to be cautious about including 3rd party software on their laptops.
In reality, they have shot my dog while collecting the initial report.
I mean, if I fired a gun at your house but was lucky enough not to injure anybody, shouldn't my punishment still be more than the cost of fixing the bullet holes? Of course that's separate from the question of whether you should receive more than the cost of fixing the bullet holes.
Sometimes putative damages can be awarded, which can look at the egregiousness of the actions of the plaintiff. I don't know if those are available here.
As to why the government hasn't tried to indict for criminal charges, there could be many reasons. The case might not be good. They might be waiting. They may think it's small fry stuff.
The doj doesn't go after everyone.
Is there any question as to what Lenovo actually did, are they denying they exceeded their authorisation in accessing computers and MitM-ing things like bank transactions? If the facts aren't in dispute there then surely the only thing the court would need to do is work out how long the directors who authorised/oversaw [or negligently didn't oversee] this are going to be put in prison for.
Let's say that some company builds a bridge that doesn't match the spec, to the point that it's dangerous. Maybe it falls down if any truck weighing more than 10 tons goes over it, when it was supposed to hold 40 tons. And let's further say that this weakness was the result of intentional cost-saving measures and a complete failure to investigate their consequences. But then let's say that the fault with the bridge was discovered after a few months before any 11-40 ton trucks had gone over it, so nobody actually died.
Would that be illegal under some sort of negligence or endangerment law? It certainly seems like it ought to be. Lenovo's actions are basically equivalent, except that it was (probably) just property at risk, not lives.
It looks like endangerment is indeed a criminal offense, and it doesn't require that the harm actually happens, just that the potential was there and that it was foreseeable. Would that actually apply here?
Regarding automobile recalls, it looks like GM got hit with some fines for their ignition switch shenanigans, beyond actual damages. But it looks like this is a regulatory thing rather than a criminal thing. Maybe this is another place where special laws get in the way of generalizing.
While it seems pretty rare for this to happen, the officers of a corporation can be held criminally liable for the actions of the corp.
Not a lawyer but quoting from the document.
COMPLAINT FOR:
1) VIOLATION OF COMPUTER FRAUD AND ABUSE ACT (18 U.S.C. § 1030, et seq.);
2) VIOLATION OF FEDERAL WIRETAP ACT (18 U.S.C. § 2510, et seq.);
3) VIOLATION OF THE STORED COMMUNICATIONS ACT (18 U.S.C. § 2701, et seq.);
4) VIOLATION OF CALIFORNIA INVASION OF PRIVACY ACT, PENAL CODE §§ 631, 637.2;
5) VIOLATION OF CALIFORNIA BUS. & PROF. CODE § 17200, et seq.;
6) TRESPASS TO CHATTELS;
7) COMMON LAW FRAUD; and
8) NEGLIGENT MISREPRESENTATION 2) VIOLATION OF FEDERAL WIRETAP ACT (18 U.S.C. § 2510, et seq.);
3) VIOLATION OF THE STORED COMMUNICATIONS ACT (18 U.S.C. § 2701, et seq.);
You'd think one or the other, no? (AFAIK Superfish didn't touch anything even remotely covered by SCA). This looks like classic "all of the torts" shotgun filing. Which makes sense for a civil case, but it's not much of a guide as to what criminal cases would be viable.But that is the guide book for criminal proceedings against individuals. The prosecutor dog piles on every single charge they can and then offers a scaled down plea bargain.
As for unfairness, I think the entrepreneurial class action system to punish very diffuse harms amounts to an inefficient regulatory regime and that inefficiency results in higher prices for everyone as compared to a more efficient system.
Re: cy pres awards, while Pearson v. NBTY (out of the 7th Circuit) did not involve a residual award, it did strongly imply that they would be unreasonable when, as here, the class members could be individually identified and compensated directly. More generally, after the 7th Circuit's recent cases on the subject, cy pres awards are low hanging fruit for objectors and plaintiffs' counsel have an incentive to structure settlements to avoid such challenges.
Without writing an entire law review article in the comments, I'd say if no government (state or federal) can be bothered, given that they could almost certainly get a fine for less than $4 million (that's a lot of GS-11 man-hours) then reliance on the reputation economy seems like a good alternative.
And while discovery can be useful for getting information, in this case the information was publicized based on the workings of a different reputation economy (the security research community).
There may be some case that slip through the cracks, but I am unconvinced that the sui generis (to the US) opt-out class action mass tort system does more good than harm.
There is the cost of removing the malware, and cleaning up any damages it caused. This is normally done by estimating how many hours a professional would spend on it, and the wages they would demand.
Second, is the for-profit claim of "TRESPASS TO CHATTELS". If someone goes and steal a car to run a taxi service, one would look at the ill-gotten gains as well as the potential economic loss the car owner might has sustained from not having access to the car. "borrowing" other peoples cars once the owner has parked it is not risk free, and the law recognize this beyond just looking at used up gasoline.
What I do normally see is the court looking for guidelines regarding damages, and here the relevant question would be what a average person would have to pay in order to remove the malware and restore damages. A laywer could present rates of reputable repair shops has charge clients, and the defense lawyer could argue that the update helped reduce the time a professional would take.
And since the malware has already been removed at no cost, the actual, not just hypothetical, answer to that question is zero.
[0] http://support.lenovo.com/us/en/product_security/superfish_u...
The US has a protection against double jeopardy. If you've been sued once for something, you cannot be sued again (and again, and again) for the same thing. In most cases this is a good thing. It means that once the case is done, it is really done.
But companies have learned how to take advantage of it. If they think they are going to have to fight a class action lawsuit that they are likely to lose, THE COMPANY will go to some lawyers, and say, "If you bring this lawsuit against us, we will cooperate fully, cave in quickly, and we'll settle on modest terms."
Said lawyers have every incentive to cooperate. It is easy money, and the more reliable they are about following through, the more of this kind of work they can get.
And companies have every incentive to do this. Because occasionally class action lawsuits happen that the company did not set up like this. That's when you get huge claims like the ones that took down big tobacco, or the hot coffee lawsuit that McDonalds faced a few years back.
Double jeopardy doesn't prevent someone from opting out of a class action lawsuit and suing separately.
>hot coffee lawsuit
The hot coffee case wasn't a class action lawsuit.
Yes. But one individual probably does not have sufficient injury to represent a meaningful case for the company. The point is that you've blocked a second, larger, class action lawsuit. Which is what the company is actually scared of.
The hot coffee case wasn't a class action lawsuit.
You're right. See http://en.wikipedia.org/wiki/Payment_Card_Interchange_Fee_an... for a more meaningful class action lawsuit.
The "hot coffee" lawsuit was well justified, as the burns were serious and McDonalds did not learn from previous instances.
Disclaimer: I'm not a lawyer etc. please ask your lawyer for legal advice.
I would love to see more information about the terms for the second lawsuit. Certainly you hear about cases with large settlements. But you don't hear about the routine cases. I don't know the mix.
That said, I do know that there are class action lawsuits which never really fix anything, no matter how many times they happen. As an example, consider printer ink. Every manufacturer has received class action lawsuits for their printers claiming to be out of ink when they are not. They have all settled them with coupons that are redeemable for amounts that are pretty meaningless. (About enough to cover one extra refill of ink.)
Did behavior change? I currently have a printer that was purchased last year, sees only light use (every month or two we'll print a few pages), and which has claimed to have run out of ink twice. It is on my mind because the second time last week. I know that there is no way it actually used up the magenta ink. But it is currently unusable.
And it works! No matter how bad my experience is, I'm not motivated to buy another printer because I have no reason to believe that any other consumer printer will be honest with me. And even with the printer lying to me, I simply don't do enough printing for it to be cost effective to buy an expensive printer that I would trust.
Hmm. I wonder if the law firm bringing the case, specified in the docket as PRITZKER LEVINE LLP, has any history of doing this.
It only applies to the extent that individuals at Lenovo receive criminal charges. Then they are only on trial once.
But if they harmed 10 people the same way, then all ten people can absolutely sue to cover the damages they sustained.
But to an extent you are right: if you've already been compensated (in the form a $5 class action coupon) for the $??? privacy harm of a rooted computer? Then too bad - you should have opted out before your class settled.
Liebeck sued McDonald's for actual costs of her medical treatment. McDonald's refused to pay for her injuries or admit fault. The jury awarded the massive punitive damages ($160,000 in actual damages and $2.7M in punitive) of their own volition, because the company's behavior was so egregious, was just one incident in an ongoing chain of similar ones (and for which they'd settled previous claims), and was obviously responsible for the third degree burns she suffered beneath her clothing.
Please check your facts next time.
https://en.wikipedia.org/wiki/Liebeck_v._McDonald%27s_Restau...
I never stated an opinion either way on whether this was a bad lawsuit. My statement was that it was a lawsuit launched without the cooperation of the company. Which is definitely true in that case.
That said I did need to check my facts because I called it a class action lawsuit when it wasn't. But that issue is completely unrelated to anything that you said.
I wouldn't call this a mistake. It is a very accurate heuristic not just in this particular case but in online discussions in general. There will be errors, but deploying a heuristic instead of a perfect algorithm makes great sense when dealing with the internet. Less acceptable for something like a scientific paper.
I'd say actually reading may be a better approach rather than to use an heuristic.
Perhaps you should read what I wrote then, because what I wrote was about a heuristic to identify intentions based on what was read. Would you suggest that in face to face discussions body language should ignored when it disagrees with what a person says?
My apologies for my ambiguity. I could have been far clearer about what I was trying to say, and my motivations for having said it.
I see both parts of the discussion are among the older members of HN, glad to see they're setting a good example :)
First off, the lawsuit was justified, but not because of the temperature of the coffee. The coffee was being served at industry standard temperatures (defined in terms of what _other_ companies in the industry serve their coffee at), despite what many claim. The primary problem is that their coffee cup design was defective, and was prone to collapsing.
In response to the lawsuit, McDonald's has not changed the temperature of their coffee. If you order a black coffee at a McDonald's today (or at many other shops), it may very well be just as hot as the coffee that disfigured Liebeck in 1994. So for the love of god, don't spill coffee on yourself! Coffee as cool as 140F can cause third degree burns in mere seconds. That is well below what anybody serves coffee at. Coffee is dangerous. It's just that simple.
http://www.burnfoundation.org/programs/resource.cfm?c=1&a=3
http://en.wikipedia.org/wiki/Liebeck_v._McDonald%27s_Restaur...
Where did this meme of "Liebeck v. McDonald's was actually 100% reasonable, and anyone who thinks otherwise is a fool" come from?
In the immediate aftermath of the lawsuit, many Americans became extremely critical of any personal injury lawsuits. It appeared as though if it continued, the livelihoods of personal injury lawyers might be threatened. So an informal propaganda campaign was launched, featuring some selective truth (the burn photographs) and some lies (the idea that the coffee served to her was way hotter than coffee you and I are used to). These sort of lawyers are extremely good at being convincing, that is pretty much their job after all, and in a non-adversarial context it is not suprising that they are able to convince most people.
Exactly. The other effect is to move the Overton window. Prior to the propaganda campaign, those of us who would have said Liebeck wasn't even entitled to compensation for her actual medical costs would have been branded as unsympathetic and a bit cold-hearted. Now, we'd be considered baby-eating monsters with opinions too radical to be a part of public discourse.
These sort of lawyers are extremely good at being convincing, that is pretty much their job after all, and in a non-adversarial context it is not suprising that they are able to convince most people.
It's like the old adage, "Don't make enemies with people who buy ink by the barrel," taken to the next level. Lawyers ru(i)n almost everything in America.
Even the main justice who created them "could not conceive of a modern function or a coherent theory for representative litigation."
Even then, rule 48 was opt-in until 1966, when a federal court rule change (IE not a law, just the court rules made up by a few federal judges) changed to make them opt-out.
This is what sprung up the industry you see today.
The rest of what you describe is simply a symptom of not building a coherent platform for mass-action, but instead a way to simplify lawsuits that involved 40 or so people.
If you do the same thing multiple times, you can be sued for each instance.
If you run a scam that affects a million people, you can face a million separate lawsuits.
You can be sued for the same act by multiple people, though you can't be sued BY THE SAME PARTY for that same act multiple times under a doctrine called res judicata.
You can usually opt out of a class action, and then sue again on your own - and you're entitled to your day in court to assert the claim against them. Though, since most people don't opt out, a class action does provide a way to settle the case with the vast majority of potential claimants.
If the defendant LOST the earlier case, they may even be precluded from re-litigating any issues resolved in it (and, by extension, prevented from defending themselves substantively). Though in some situations, like if it were easy for the claimant to join the earlier lawsuit, this may not be so. See Parklane Hosiery Co. v. Shore, 439 U.S. 322 (1979).
I think you are drastically underestimating this. $4M likely won't cover the bill for making copies of the discovery. Firms in similarly underwhelming class action cases have received $50M-$100M.
It's interesting that they are sticking to the original narrative when the situation was actually far worse as I originally disclosed here on HN & which was later written about by Filippo Valsorda on his blog.
Original discovery: https://news.ycombinator.com/item?id=9078536
Filippo's blog post: https://blog.filippo.io/komodia-superfish-ssl-validation-is-...
That's a particularly damning accusation.
It's a lot easier to add HP's drivers to a base image than it is to turn a HP base windows install into something configured the way we want.
I like that you said spyware, whether intentionally or not.
Most people call these programs "crapware," "junkware," "bloatware," or third-party pre-installed software. Though generally speaking this third-party junkware isn't expressly designed to be spyware. Nevertheless, with cases like Superfish, the line between spyware and junkware is vanishingly faint.
Everybody, included non technically literate people call this spyware. This is where names like "spybot search and destroy" come from.
The Morris worm infected 2-3 orders of magnitude fewer computers...
Put another way, as dreadful as it is, Superfish was never at risk of partitioning the internet. The harm is restricted to those luckless individuals who purchased a Lenovo laptop in the particular time frame at issue; quite possibly a crime, but not, playing devil's advocate for reluctant prosecutors, a 'something must be seen to be done or I'll be lynched' level crime.
Whatever would happen in that situation should happen here. I would guess prison time would be involved.
Also, the way the law is structured, it's typically easier to get information in a civil suit since defendants have fewer rights.
I found a reference to a case in Utah. http://e-discoveryteam.com/2011/04/10/judge-refers-defendant...
"It also criminalizes the act of circumventing an access control, whether or not there is actual infringement of copyright itself."
https://en.wikipedia.org/wiki/Digital_Millennium_Copyright_A...
EDIT: Considering the huge number of victims systematically targeted on an ongoing basis, perhaps RICO would apply too. Certainly RICO is brought to bear by prosecutors when trying to intimidate less resourced individuals.
https://en.wikipedia.org/wiki/Racketeer_Influenced_and_Corru...
On a more serious note, what happens to the author[ing company] of the software used to inject ads? http://www.komodia.com/about
Think this insane? Look up in rem jurisdiction. You'll see cool lawsuits such as "UNITED STATES V. $50,000 IN CASH". I'd consider that precedent.
Specifically, they are C-style arrays of people.
In C, if you try to qualify (const or volatile) an array, it's actually the element-type that gets qualified.
(The straight syntax doesn't support it at all; the above applies if you try to create an typedef for the array type and then use it as a declaration specifier, side by side with qualifiers.)
In the same way that qualifiers on C arrays slide down to the elements, certain attributes, including responsibilities, have to shift from corporations to the member individuals.
It's got IE5, Stuffit Expander, Netscape Communicator 4.7.7, and Outlook Express 5.0.2, and Java.
iTunes on OS X runs better than any other music apps (that are not command line music clients like ncmpcpp) I've used, and I've used a lot. On OS X, I can't see why people would call it bloatware/crapware.
While that's technically better than no option at all, it doesn't make me miss them too much.
https://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootk...
http://www.microsoftstore.com/store/msusa/en_US/cat/Signatur...
Apparently they do still include Windows Defender, which is described as "free anti-virus protection that never expires". Although it's a Microsoft product, I would place it close to third party junkware on the scale: in my experience, it often turns out to be the culprit if performance degrades over time, every now and then an update will completely break a box requiring some sort of restore disc or similar to get back up and running, and in any case it seems to add little value being so much less effective these days than a lot of other security software. At least it probably uninstalls cleanly if you do want to swap it out, though.
I found this an interesting, if somewhat inflammatory, criticism of the same Windows Signature programme:
http://www.techradar.com/news/software/operating-systems/mic...
Sadly, the UK version of the Microsoft Store seems to have a very limited range of devices available on the same basis.
1) "crapware" is not well-defined for all users, some utility that absolutely is annoying and unnecessary to medium to advanced users may be found useful by complete novices, e.g. the prototypical "your grandma".
2) The bigger cause is, of course, affiliate money. Companies have little backlash to crapware other than perhaps some lost sales due to disgruntled users. That's hard to quantify. The money you get from an affiliate whose crapware you preinstall is absolutely easy to quantify, though. This is definitely the mode of operation for cell phone companies. My Verizon phone comes with NFL apps and other crap that I can't even uninstall.
3) In lost cases, though, it's the companies own additional software that is the crapware. Again, the cause is money, the tracking and/or usage data is worth a lot of money.
Unless there is a big punishment, large enough to really hurt these huge companies, the status quo will continue. That's why this particular lawsuit is so important.
The rest is totally right, though. For any behavior by a company that seems to do more harm than good, you can usually trace it back to some decision-maker who is rewarded for the good parts but is not responsible for the bad parts. If your decisions cause $1 in gain for your department and $2 in loss for another department, many companies aren't smart enough to do anything but reward you and punish the other department.
https://en.wikipedia.org/wiki/Bundling_of_Microsoft_Windows#...
I downvoted your comment because of your implication that spyware wouldn't be a problem if only everyone were as sophisticated as you.
You made a counterpoint, you didn't insult (the use of the word 'nonsense' is really common on HN counterpoints), you downvoted, then you explained your reason for the downvote. In all this now flame-wars were set.
I hope a lot of us will follow your path and make HN pleasant for everyone.
Thank you.
Me? I believe it's great that I live in a free country where I can buy a new motorcycle and not have to take it apart to make it safe to use, or consider engine-building skill to be essential.
And as much as I enjoy working with software, I don't think reinstalling windows just to avoid spyware should be considered essential, or that regular people should have to know how to do it. For your regular Mr or Mrs Smith reinstalling is not a valuable skill - computers are tools which should just work.
Strangely enough, Linux often works flawlessly with these same computers.
I used to think RMS was paranoid with his fully open source stack, Lenovo has me questioning that belief.
The software was pre-installed on the machines. I guess it probably depends on what the user terms were for it. The statue requires "without authorization."
I'm surprised there isn't a negligence or products liability claim in here. Because one of the biggest problems, isn't' that they MTTM attacked HTTPS to inject ads, but they did it in a way that was recklessly insecure.
EDIT: omg, it's a unicorn of bad web design. The video loads on every page of this website.
I've explained time and time again why this is a bad idea, but some people really want their video on every page..
I've had clients request a video on every page - and sometimes they come back to me with "I was browsing my website and that video is annoying to have on every page. Please make it only the home page."
This is it
However, there is a happy ending to this story. I went through my credit card company to get a refund, and it was taken care of no problem. The CC company was incredibly responsive and shocked about SuperFish.
I'm quite pleased, as SuperFish aside, this is the worst computer I've ever owned (Y50 UHD.)
The chargeback just went through successfully on Friday. I have not heard anything from Lenovo yet regarding returning the laptop. I can keep you updated on this if you like.
The woman at MasterCard was very helpful and knowledgeable. She was surprised about SuperFish, but seemed to understand it. I use the laptop professionally and do systems work, so I explained how I basically could not use the laptop for work and had to spend time double-checking some of the work I had already done for clients.
There are also annoying hardware issues with this laptop, various intermittent problems causing crashes. I didn't get into that though, and just stuck with the Lenovo omitting fraud / laptop unusable for work narrative.
I always heard good things about Lenovo, but the late delivery, SuperFish, and hardware issues are enough to make me avoid the company like the plague.
Historically, the Thinkpad brand was a gold standard in business notebooks, but they have sadly devolved into poor followers of Apple. Hopefully the Thinkpad brand can rediscover its innovative roots.
> "I always heard good things about Lenovo, but the late delivery, SuperFish, and hardware issues are enough to make me avoid the company like the plague."
"Good things about Lenovo" are usually in reference to the Thinkpad brand. The GP's hardware issues are unrelated to the historical reputation of the Thinkpad brand.
What's worse though is that they apparently don't have any QA whatsoever since they pushed an update that made the device basically unusable (keywords: Nexus 7 2012 Android 5).
Not running crapware is theft, just like not watching commercials is theft. The only way they can afford to sell you a PC at those prices is by subsidizing their profit with crapware income. /s
Plus you need to have a separate OS license as well to make it work.
It's challenging because most people can't install an OS.
The software you will want from Lenovo is their System Updater which can be installed on a fresh (non-Lenovo) Windows install, and will let you install drivers and similar software (nothing is forced, all up to you).
The one thing you won't be able to install the various pieces of crapware, but that is a benefit.
http://www.theverge.com/2015/2/20/8077033/superfish-fix-micr...