Hard Light Productions Forums

Off-Topic Discussion => General Discussion => Topic started by: Bobboau on February 19, 2015, 09:47:12 am

Title: Lenovo caught intentionally shipping man-in-the-middle spyware
Post by: Bobboau on February 19, 2015, 09:47:12 am
http://www.theregister.co.uk/2015/02/19/superfish_lenovo_spyware/
Title: Re: Lenovo caught intentionally shipping man-in-the-middle spyware
Post by: Thisisaverylongusername on February 19, 2015, 01:04:31 pm
Anybody who has stock in Lenovo better sell fast. It's not going to be high very mush longer.
Title: Re: Lenovo caught intentionally shipping man-in-the-middle spyware
Post by: jr2 on February 19, 2015, 03:26:05 pm
Their stock will turn to mush.. quickly.

Yeah, I saw this on Reddit and was like :wtf:
Title: Re: Lenovo caught intentionally shipping man-in-the-middle spyware
Post by: Klaustrophobia on February 19, 2015, 04:31:39 pm
Honestly I'm surprised this is the first time anyone's been caught doing it.  I have a hard time believing all the other companies haven't snuck something untoward to at least some degree in their bloatware.  Maybe not full on ad hijacking.
Title: Re: Lenovo caught intentionally shipping man-in-the-middle spyware
Post by: An4ximandros on February 19, 2015, 05:45:51 pm
All of my CEP's pcs are Lenovo... :nervous:
Title: Re: Lenovo caught intentionally shipping man-in-the-middle spyware
Post by: deathfun on February 20, 2015, 12:33:34 am
Glad I don't have that on my computer
Got my lenovo about a year ago

Title: Re: Lenovo caught intentionally shipping man-in-the-middle spyware
Post by: headdie on February 20, 2015, 01:45:48 am
be interesting to see how many business involved in e-commerce have affected machines
Title: Re: Lenovo caught intentionally shipping man-in-the-middle spyware
Post by: Bobboau on February 20, 2015, 10:39:40 am
I've seen a bunch of people say 'their stock is gona crash', it's not crashing.
Title: Re: Lenovo caught intentionally shipping man-in-the-middle spyware
Post by: 666maslo666 on February 20, 2015, 11:39:20 am
I have recently bought Lenovo laptop, luckily it came without an OS preinstalled.
Title: Re: Lenovo caught intentionally shipping man-in-the-middle spyware
Post by: The E on February 20, 2015, 12:12:54 pm
Latest news: MS has updated Windows Defender to kill Superfish on sight (http://pastebin.com/raw.php?i=us7iXvkn).
Title: Re: Lenovo caught intentionally shipping man-in-the-middle spyware
Post by: jr2 on February 20, 2015, 07:59:01 pm
:yes:
Title: Re: Lenovo caught intentionally shipping man-in-the-middle spyware
Post by: Phantom Hoover on February 21, 2015, 04:02:37 am
Latest news: MS has updated Windows Defender to kill Superfish on sight (http://pastebin.com/raw.php?i=us7iXvkn).

But does that remove the Superfish cert key? That's just as important for security as removing the software itself.
Title: Re: Lenovo caught intentionally shipping man-in-the-middle spyware
Post by: The E on February 21, 2015, 04:23:19 am
Yes, it does.
Title: Re: Lenovo caught intentionally shipping man-in-the-middle spyware
Post by: LHN91 on February 21, 2015, 06:05:40 am
It handles the root cert for Windows but does not handle the Firefox and Thunderbird cert stores, they use ones separate from the Windows one.
Title: Re: Lenovo caught intentionally shipping man-in-the-middle spyware
Post by: jr2 on February 24, 2015, 08:42:29 am
Intentional, or not?  :drevii:
Title: Re: Lenovo caught intentionally shipping man-in-the-middle spyware
Post by: An4ximandros on February 24, 2015, 09:22:09 am
Ehm. MS needs to make sure its **** works, not someone else's. :p
Title: Re: Lenovo caught intentionally shipping man-in-the-middle spyware
Post by: jr2 on February 24, 2015, 09:29:00 am
Umm, until it steps into the anti-malware business, because then, it needs to make sure your system is secure and works, not just the parts of it that happen to be designed by MS.  Imagine if AVG, Avira, Comodo, Kaspersky, BitDefender, Malwarebytes, et al did this...
Title: Re: Lenovo caught intentionally shipping man-in-the-middle spyware
Post by: S-99 on February 26, 2015, 07:19:19 pm
Don't forget pokki start menu that they also include. I've fixed numerous pokki start menu infections. Pokki keeps installing and installing and installing. It's rather aggressive. Dealt with this numerous times at my new job for client and customer computers.
Title: Re: Lenovo caught intentionally shipping man-in-the-middle spyware
Post by: Klaustrophobia on February 27, 2015, 01:13:04 am
I finally found a new laptop that meets my requirements.  It's a lenovo though. :/  Anyone know how easy it is to get a hold of a clean install ISO for windows 8.1?  Or maybe I'll just buy a copy of 7.  They can't be that expensive any more right? (yeah right)
Title: Re: Lenovo caught intentionally shipping man-in-the-middle spyware
Post by: headdie on February 27, 2015, 01:25:41 am
how old is the laptop?
Title: Re: Lenovo caught intentionally shipping man-in-the-middle spyware
Post by: Klaustrophobia on February 27, 2015, 01:34:02 am
My current one is from 2006.  The new one I haven't bought yet.  I have no idea when it shipped to the retailer, but it seems to not be this year's model as it's not on Lenovo's website without searching for it.
Title: Re: Lenovo caught intentionally shipping man-in-the-middle spyware
Post by: jr2 on February 27, 2015, 04:58:02 pm
I think you can D'L an 8.1 ISO from M$ (or verify the checksum from a non-M$ source with the M$ one) and install that using your 8.1 key on the bottom of the laptop.  Has worked for me with 7.
Title: Re: Lenovo caught intentionally shipping man-in-the-middle spyware
Post by: BirdofPrey on February 27, 2015, 05:54:26 pm
Don't windows 8 machines have the full OS on the recovery partition
Title: Re: Lenovo caught intentionally shipping man-in-the-middle spyware
Post by: Klaustrophobia on February 27, 2015, 08:32:18 pm
The recovery partition includes the OEM bloatware.  They also don't put the key on the bottom of the laptop (or anywhere else).  You have to use some utility that will read it for you.
Title: Re: Lenovo caught intentionally shipping man-in-the-middle spyware
Post by: S-99 on February 27, 2015, 09:14:46 pm
For legitimate microsoft windows 7 iso recovery (http://www.microsoft.com/en-us/software-recovery). And for legitimate microsoft windows 8 media installation creation (http://windows.microsoft.com/en-us/windows-8/create-reset-refresh-media).

The windows 7 link should give you a download to windows 7 if you have a valid key to authorize a download. For windows 8 media creation, you should be able to create an installable iso. However, i don't know very much about the media creation tool.

These technically should both give an escape to inclusive bloatware.