Jump to content

Lenovo caught installing adware on new computers


Recommended Posts

Posted (edited)

It's for this reason I always re-install the operating system from scratch on new Windows computers. :(

 

Source: The Next Web

 

It looks like Lenovo has been installing adware onto new consumer computers from the company that activates when taken out of the box for the first time.

 

The adware, named Superfish, is reportedly installed on a number of Lenovo’s consumer laptops out of the box. The software injects third-party ads on Google searches and websites without the user’s permission.

 

Superfish appears to affect Internet Explorer and Google Chrome on these Lenovo computers.

 

Other users are reporting that the adware actually installs its own self-signed certificate authority which effectively allows the software to snoop on secure connections, like banking websites as pictured in action below.

 

This is a malicious technique commonly known as a man-in-the middle attack, where the certificate allows the software to decrypt secure requests, yet Lenovo appears to be shipping this software with some of its products out of the box.

 

If this is true — we’ve only seen screenshots so far — Superfish could be far more dangerous than just inserting advertising.

 

Superfish is identified by antivirus products as adware and advised to be removed. One user created a video that details how to remove the software manually, for those that are affected.

 

Even though Hopkins says the company has stopped installing the software on computers, it appears that’s only “temporary” until the company behind the software makes some tweaks to stop pop-ups.

 

Reports of Superfish being pre-loaded on Lenovo computers have appeared on forums as early as mid-2014.

 

If this is as widespread as it appears to be, the news is not good for Lenovo computer owners. If you own a Lenovo machine, let us know in the comments if you find the Superfish software on your machine.

 

http://a.pomf.se/bcvxjf.png

Edited by Arthur
  • Thanks 1
Posted

I just don't use Lenovo computers anyways, as they tried to tell me at BETT that the school vision on ICT was completely wrong and had to be changed.

 

Needless to say I walked off before having a repeat of my Pearson Incident from the year before, where I ended up winning after about 45 mins of very stubborn conversations that ended up with 5 of the reps around me at their stand.

  • Thanks 1
Posted
It's for this reason I always re-install the operating system from scratch on new Windows computers. :(

 

What do you recommend when you don't have a volume licencing agreement?

 

Mostly applies for personal use, but could apply in school where the PCs have been bought with the required perpetual licences.

 

My understanding is that you're only allowed to re-image with the OEM recovery media unless you have bought a full retail version for each machine or have a volume licencing agreement. Presumably the recovery discs that come with the machine have the same crapware installed as the build on the machine.

Posted (edited)
What do you recommend when you don't have a volume licensing agreement?

For home PCs Microsoft now provide a means to download the proper install media for both Windows 7 and Windows 8.1.

 

My understanding is that you're only allowed to re-image with the OEM recovery media unless you have bought a full retail version for each machine or have a volume licensing agreement.

If a school or business doesn't have a volume licensing agreement, you can do what the article below describes.

 

Legally deploying Windows images to OEM licensed PCs

 

What if you company does not have a VL agreement? You need to 5 products to start one. You can buy a single copy of Windows (to get the ISO download and MAK/KMS keys) and 4 cheap dummy CALs – now you have a VL at minimum cost, and you can re-image your OEM-licensed PCs with an image made from your VL media.

Presumably the recovery discs that come with the machine have the same crapware installed as the build on the machine.

Correct! :(

Edited by Arthur
  • Thanks 1
Posted

This is stupid! Superfish store a copy of the encrypted private key for the certificate they use to intercept HTTPS connections with inside an executable on every Lenovo PC with this adware. All we need now if for someone to guess/crack the password. :(

 

It's troubling that Superfish and Lenovo are using such proxies to see secure data for advertising purposes, but third parties may also be able to get their hands on private information. It appears as though Superfish has used the same private key for its spurious root certificate on every machine. As Eric Rand, researcher at Brown Hat Security, explained to The Verge, if someone was able to crack the key, nefarious individuals could create certificates that all Lenovo machines inherently trust, or write malicious software that all Lenovo machines see as trusted programs. (Source)

 

http://a.pomf.se/ppoery.png

Posted (edited)

Sadly this doesn't surprise me one little bit. These computers are made in Comunist China afterall - heck so are a heap of other brands. As to the statement above by @ZeroHour that Lenovo is pretty crapware free I must say I read that with a fair bit of surprise. The ones we have bought over recent years come pretty heavily laden with the darned stuff. What came as a huge surprise to me was to be told by a warranty repair visiting Tech that I should always use the Lenovo update tool and avoid getting updates selected by Microsoft. Worrying.

 

I'm wondering if this thread would be better located where it's less easily visible?

Edited by speckytecky
Posted (edited)

This is what Lenovo have to say.

 

https://forums.lenovo.com/t5/Lenovo-P-Y-and-Z-series/Lenovo-Pre-instaling-adware-spam-Superfish-powerd-by/m-p/1863174#M79882

 

Due to some issues (browser pop up behavior for example), with the Superfish Visual Discovery browser add-on, we have temporarily removed Superfish from our consumer systems until such time as Superfish is able to provide a software build that addresses these issues. As for units already in market, we have requested that Superfish auto-update a fix that addresses these issues.

 

To be clear, Superfish comes with Lenovo consumer products only and is a technology that helps users find and discover products visually. The technology instantly analyzes images on the web and presents identical and similar product offers that may have lower prices, helping users search for images without knowing exactly what an item is called or how to describe it in a typical text-based search engine.

 

The Superfish Visual Discovery engine analyzes an image 100% algorithmically, providing similar and near identical images in real time without the need for text tags or human intervention. When a user is interested in a product, Superfish will search instantly among more than 70,000 stores to find similar items and compare prices so the user can make the best decision on product and price.

 

Superfish technology is purely based on contextual/image and not behavioral. It does not profile nor monitor user behavior. It does not record user information. It does not know who the user is. Users are not tracked nor re-targeted. Every session is independent. When using Superfish for the first time, the user is presented the Terms of Use and Privacy Policy, and has option not to accept these terms, i.e., Superfish is then disabled.

 

Edit. Do Lenovo seriously believe they were doing customers a favour by bundling Superfish? :confused:

 

http://news.lenovo.com/article_display.cfm?article_id=1929

 

Superfish was previously included on some consumer notebook products shipped in a short window between September and December to help customers potentially discover interesting products while shopping. However, user feedback was not positive, and we responded quickly and decisively:

 

Superfish has completely disabled server side interactions (since January) on all Lenovo products so that the product is no longer active. This disables Superfish for all products in market.

  • Lenovo stopped preloading the software in January.
  • We will not preload this software in the future.

We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns. But we know that users reacted to this issue with concern, and so we have taken direct action to stop shipping any products with this software. We will continue to review what we do and how we do it in order to ensure we put our user needs, experience and priorities first.

 

To be clear, Superfish technology is purely based on contextual/image and not behavioral. It does not profile nor monitor user behavior. It does not record user information. It does not know who the user is. Users are not tracked nor re-targeted. Every session is independent. Users are given a choice whether or not to use the product. The relationship with Superfish is not financially significant; our goal was to enhance the experience for users. We recognize that the software did not meet that goal and have acted quickly and decisively.

 

We are providing support on our forums for any user with concerns. Our goal is to find technologies that best serve users. In this case, we have responded quickly to negative feedback, and taken decisive actions to ensure that we address these concerns. If users still wish to take further action, detailed information is available at http://forums.lenovo.com.

Edited by Arthur
Posted

The password for the certificates private key has now been discovered. :eek:

 

Extracting the SuperFish certificate

 

I extracted the certificate from the SuperFish adware and cracked the password (":censored:") that encrypted it. I discuss how down below. The consequence is that I can intercept the encrypted communications of SuperFish's victims (people with Lenovo laptops) while hanging out near them at a cafe wifi hotspot. Note: this is probably trafficking in illegal access devices under the proposed revisions to the CFAA, so get it now before they change the law.
Posted
Lenovo has released a list of models that may have had Superfish installed.

 

G Series: G410, G510, G710, G40-70, G50-70, G40-30, G50-30, G40-45, G50-45

U Series: U330P, U430P, U330Touch, U430Touch, U530Touch

Y Series: Y430P, Y40-70, Y50-70

Z Series: Z40-75, Z50-75, Z40-70, Z50-70

S Series: S310, S410, S40-70, S415, S415Touch, S20-30, S20-30Touch

Flex Series: Flex2 14D, Flex2 15D, Flex2 14, Flex2 15, Flex2 14(BTM), Flex2 15(BTM), Flex 10

MIIX Series: MIIX2-8, MIIX2-10, MIIX2-11

YOGA Series: YOGA2Pro-13, YOGA2-13, YOGA2-11BTM, YOGA2-11HSW

E Series: E10-30

 

Source: http://arstechnica.com/security/2015/02/lenovo-pcs-ship-with-man-in-the-middle-adware-that-breaks-https-connections

 

As to the statement above by @ZeroHour that Lenovo is pretty crapware free I must say I read that with a fair bit of surprise.

Me too. The Yoga 3 Pro has tons of junk.

 

http://a.pomf.se/ekvfqp.jpg

 

http://a.pomf.se/rrnoim.jpg

Posted

@jmak. This article might be of interest.

 

Save yourself from your OEM’s bad decisions with a clean install of Windows 8.1 « Ars Technica

 

Crapware is a fact of life for Windows PC buyers. Most of the time, it's relatively harmless: limited anti-virus subscriptions you don't want, WildTangent games, and demoware you don't need, and Microsoft Office demos you can't use without spending more money. Sometimes, as we've seen with today's "Superfish" news, it can be actively harmful, putting users' security at risk.

 

With some effort, this unwanted and unsafe software can usually be uninstalled. If you have an affected Lenovo PC, we've outlined the multi-step process for removing the software and the root certificate here.

 

If you want to be sure that everything is completely removed (and if you're willing to do the work), the more comprehensive solution is to completely reinstall Windows yourself. It's not for everyone, but there are benefits to doing it this way—you get a totally clean PC that you're in full control over.

 

Most OEMs don't include vanilla Windows install media with their systems anymore. They usually opt to include a restore partition, and that restore image usually has all the same crapware in it that shipped with the PC in the first place. We never updated our Windows 7 and 8 install guides with information about Windows 8.1, but there are a few differences, mostly positive. We'll walk you through the basics of getting install media, installing Windows, and creating a new clean recovery image.

  • Thanks 1
Posted
Sorry I am meaning Lenovo of a few years back (when I last had one) I found it to be great and others models seemed okay too but I have not had a play with one for a while now.
Posted
@jmak. This article might be of interest.

 

 

thanks Arthur - good guide. It's not so much what's possible that is the difficulty - I've built plenty of windows PCs, but even though the licence key will activate using methods like that, my interpretation of the MS documentation is that it's not permitted.

Posted
I just don't use Lenovo computers anyways, as they tried to tell me at BETT that the school vision on ICT was completely wrong and had to be changed.

 

Needless to say I walked off before having a repeat of my Pearson Incident from the year before, where I ended up winning after about 45 mins of very stubborn conversations that ended up with 5 of the reps around me at their stand.

 

That was hilarious Garry, I couldn't believe what I was witnessing! "No you don't want to do it that way, that's crazy, you want to do it this way, blah, blah"

Posted
That was hilarious Garry, I couldn't believe what I was witnessing! "No you don't want to do it that way, that's crazy, you want to do it this way, blah, blah"

 

Anyone manage to get a video recording of that !! ???

Posted
We have a bunch of Acer Laptop's here. All I did was install a fresh image of Windows 7 and used the license key on the back and they all activated just fine... I do this for all family as well and tell anyone when they buy and PC to install a fresh image of Windows on it. You avoid all this carp then.
Posted
Sorry for hijacking the thread; Sadly no.. @BKGarry's face was a picture though (think Jean Luc Picard face palm). I think he saw the VeryPC hoodies we were wearing, overheard us maybe identifying why some of the devices on their stand wouldn't be appropriate, and decided he wanted a ruck. I was dumbstruck. After being on the @Millgate stand moments before and seeing how they spoke to customers it was like we'd slipped into an alternate universe.
  • Thanks 2
Posted
I was ready to attack big time. They didn't like it when I pointed out that the Yoga was useless in tablet mode as it kept the trackpad active. Then the line of well if you want a table this isn't really what you need as you don't have the back facing camera which people love. I did want to go, well why have you made them then!
  • Thanks 2
Posted
I was ready to attack big time. They didn't like it when I pointed out that the Yoga was useless in tablet mode as it kept the trackpad active. Then the line of well if you want a table this isn't really what you need as you don't have the back facing camera which people love. I did want to go, well why have you made them then!

 

I could have done with a good laugh so bit of a shame there was no video lol

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...