But that's what Superfish was as well. Why are you willing to give Superfish a free pass on doing the same thing?
But that's what Superfish was as well. Why are you willing to give Superfish a free pass on doing the same thing?
However, they knew full well what they consequences of this mechanism would be[0]. I find it impossible to believe that there was no person at any point along the chain who knew that MITMing all connections would be a security vulnerability[1]. And if that somehow managed to be the case, that makes them even less credible in my mind, since they're an OEM. They really have no excuse.
[0] I mean, seriously, just look at the name "Superfish". That's not a catchy phrase invented to publicize the vulnerability, like "Heartbleed" and "Shellshock". That's the actual name of the company whose product Lenovo bought.
I'd be mad at Lenovo - because they installed the malware without considering the consequence. I can, however, believe that plenty of decision making people at lenovo were unaware of the risks underlying the software.
So, does lenovo have more in common with the consumer who did something dumb based on poor information, or with the vendor distributing malware.