Jump to content

Lenovo caught installing adware on new computers


Recommended Posts

Posted
BETT is always January, anyways *GRRRRR shaking fist at Lenovo* for their sneaky malware installed on machines :-)

 

Erase / Format Hard Drive - Use your own image of which ever version of windows so 7 / 8 or 8.1 ( 10 when it is released ) and away you go :D

Posted
my interpretation of the MS documentation is that it's not permitted.

Given that Microsoft created a tool specifically for end users to download an ISO of the version of Windows they are licensed for you would have thought it was permitted. If not, Microsoft are breaking their own EULA. :)

  • Thanks 1
Posted (edited)

It doesn't look like Lenovo's CTO knows much about security. :eek:

 

https://github.com/0xPoly/Superphish

 

Peter Hortensius, Lenovo CTO, in an interview with Wall Street Journal:

 

"We’re not trying to get into an argument with the security guys. They’re dealing with theoretical concerns."

This script will silently intercept SSL connections made from computers infected with Superfish malware on the local network. All traffic will be logged into 'superphish.log'. Works in three stages:

 

  • Activates packet forwarding
  • ARP poisoning
  • SSL interception with Superfish CA keys

 

Here's a link to the WSJ article...

 

http://blogs.wsj.com/digits/2015/02/19/lenovo-cto-were-working-to-wipe-superfish-app-off-of-pcs

 

WSJ: What are you doing now to ensure the security of people who bought Lenovo laptops with the Superfish app?

Hortensius: As soon as the programmer is finished, we will provide a tool that removes all traces of the app from people’s laptops; this goes further than simply uninstalling the app. Once the app-wiping software is finished tonight or tomorrow, we’ll issue a press release with information on how to get it.

 

WSJ: There seems to be a disparity between what security researchers are saying about the potential dangers of this Superfish software, and what the company has said about this app not presenting a security risk.

Hortensius: We’re not trying to get into an argument with the security guys. They’re dealing with theoretical concerns. We have no insight that anything nefarious has occurred. But we agree that this was not something we want to have on the system, and we realized we needed to do more.

 

WSJ: Do you do due diligence on software you pre-install on Lenovo machines to make sure it’s secure?

Hortensius: Yes, we do. Obviously in this case we didn't do enough. The intent of loading this tool was to help enhance our users’ shopping experience. The feedback from users was that it wasn’t useful, and that’s why we turned it off. Our reputation is everything and our products are ultimately how we have our reputation.

 

WSJ: Isn't the best prevention tool to simply stop pre-loading any software on Lenovo computers?

Hortensius: In general, we get pretty good feedback from users on what software we pre-install on computers. What we’re going to do in the next few weeks is dig deeper, and work with users, industry experts and others to see how we can improve what we do around software that comes installed on consumers’ computers. The outcome could be a clearer description of what software is on a user’s machine, and why it’s there.

Edited by Arthur
  • Thanks 1
Posted

Microsoft updates Windows Defender, fries Superfish like a piece of Carp that it is

 

Microsoft has pushed out an update to Windows Defender that kills Superfish. As you can see in the image, Windows Defender is removing the Superfish certificate and frying it like the piece of Carp that it is.

 

The good news is that this will help protect those who were not aware of issue or did not know how to remove the certificate. But, all is not perfect, as Filippo Valsorda notes on Twitter, the Firefox certificate remains in place.

 

http://a.pomf.se/lkusrb.jpg

Posted

The Lenovo press statement here has a rather disturbing quote: Lenovo Newsroom | LENOVO STATEMENT ON SUPERFISH

 

LENOVO STATEMENT ON SUPERFISH

At Lenovo, we make every effort to provide a great user experience for our customers. We know that millions of people rely on our devices every day, and it is our responsibility to deliver quality, reliability, innovation and security to each and every customer. In our effort to enhance our user experience, we pre-installed a piece of third-party software, Superfish (based in Palo Alto, CA), on some of our consumer notebooks. The goal was to improve the shopping experience using their visual discovery techniques.

In reality, we had customer complaints about the software. We acted swiftly and decisively once these concerns began to be raised. We apologize for causing any concern to any users for any reason – and we are always trying to learn from experience and improve what we do and how we do it.

We stopped the preloads beginning in January. We shut down the server connections that enable the software (also in January), and we are providing online resources to help users remove this software. Finally, we are working directly with Superfish and with other industry partners to ensure we address any possible security issues now and in the future. Detailed information on these activities and tools for software removal are available here:

Superfish Vulnerability - Lenovo Support (US)

Superfish Uninstall Instructions - Lenovo Support (US)

 

To be clear: Lenovo never installed this software on any ThinkPad notebooks, nor any desktops, tablets, smartphones or servers; and it is no longer being installed on any Lenovo device. In addition, we are going to spend the next few weeks digging in on this issue, learning what we can do better. We will talk with partners, industry experts and our users. We will get their feedback. By the end of this month, we will announce a plan to help lead Lenovo and our industry forward with deeper knowledge, more understanding and even greater focus on issues surrounding adware, pre-installs and security. We are confident in our products, committed to this effort and determined to keep improving the experience for our users around the world.

 

Superfish may have appeared on these models:

G Series: G410, G510, G710, G40-70, G50-70, G40-30, G50-30, G40-45, G50-45

U Series: U330P, U430P, U330Touch, U430Touch, U530Touch

Y Series: Y430P, Y40-70, Y50-70

Z Series: Z40-75, Z50-75, Z40-70, Z50-70

S Series: S310, S410, S40-70, S415, S415Touch, S20-30, S20-30Touch

Flex Series: Flex2 14D, Flex2 15D, Flex2 14, Flex2 15, Flex2 14(BTM), Flex2 15(BTM), Flex 10

MIIX Series: MIIX2-8, MIIX2-10, MIIX2-11

YOGA Series: YOGA2Pro-13, YOGA2-13, YOGA2-11BTM, YOGA2-11HSW

E Series: E10-30

 

 

 

I think what they may possibly be trying to say is that they allowed Superfish as bloatware to be installed but were unaware of it's capabilities, which makes it doubly bad because it means no one is checking exactly what is being installed on their machines by third parties prior to shipping.

It's right up there with Sony's fail about 10 years back: Sony BMG copy protection rootkit scandal - Wikipedia, the free encyclopedia

Posted
Given that Microsoft created a tool specifically for end users to download an ISO of the version of Windows they are licensed for you would have thought it was permitted. If not, Microsoft are breaking their own EULA. :)

 

Quite clearly getting myself mixed up between re-imaging rights for volume/business and general licensing. Just incase anyone else stumbles across this thread, @Arthurs's link takes you to Windows 8. I have now found MS's page for Windows 7:

 

http://http://www.microsoft.com/en-us/software-recovery

 

New faith in Microsoft - I always assume the worst, but then at least I sometimes get a pleasant surprise B)

Posted

Lol @Arthur I completely agree. And realistically even this specific adblocking software isn't 'worse' as it's the same vulnerability.

Probably a wider-used program, though, which I suppose makes it 'worse' by scope of how many people it's affecting..

Posted

It gets worse for Lenovo.

 

Attackers protesting Superfish debacle hijack Lenovo e-mail, spoof website « Ars Technica

 

Almost a week after revelations surfaced that Lenovo preinstalled dangerous ad-injecting software on consumer laptops, attackers took complete control of the company's valuable Lenovo.com domain name, a coup that allowed them to intercept the PC maker's e-mail and impersonate its Web pages.

 

The hijacking was the result of someone compromising a Lenovo account at domain registrar Web Commerce Communications, and changing the IP address that gets called when people typed Lenovo.com into their Web browsers or e-mail applications. As a result, the legitimate Lenovo servers were bypassed and replaced with one that was controlled by the attackers. Marc Rogers, a principal security researcher at content delivery network CloudFlare, told Ars the new IP address pointed to a site hosted behind his company's name servers. CloudFlare has seized the customer's account, and at the time this post was being prepared, company engineers were working to help Lenovo restore normal e-mail and website operations.

 

"We took control as soon as we found out (minutes after it happened) and are now working with Lenovo to restore service," Rogers said. "All we saw was the domain come in to us, at which point we took immediate action to protect them and their service."

 

http://a.pomf.se/ymybbc.png

Posted

 

An important point that's often lost in news coverage of domain name hijackings is that the attackers responsible don't actually compromise the servers of the targeted company. Rather, the attackers cause people trying to send e-mail or visit Web pages to bypass the targeted company's servers and instead access attacker-controlled servers, often with few indications to end users that there's anything amiss.

Finally! Thank you someone for finally saying it (even if it's not the journalists that ought to be saying it) - it really irks me when 'hackers' do a DNS redirection and suddenly the papers hail them Timothy McGee incarnate.

Posted (edited)

No more bloatware or adware on Lenovo's! :eek:

 

http://news.lenovo.com/article_display.cfm?article_id=1934

 

We are starting immediately, and by the time we launch our Windows 10 products, our standard image will only include the operating system and related software, software required to make hardware work well (for example, when we include unique hardware in our devices, like a 3D camera), security software and Lenovo applications. This should eliminate what our industry calls “adware” and “bloatware.” For some countries, certain applications customarily expected by users will also be included.

 

Hopefully that includes Pokki too.

 

www.channelregister.co.uk/2015/02/25/lenovo_pokki/

Edited by Arthur
  • 3 weeks later...
Posted

Microsoft's malware detection data shows that Lenovo's crapware has been scrubbed from about 250,000 Windows PCs

 

Microsoft earlier this week said that search-and-destroy work by it, Lenovo and other software makers has reduced the daily number of Lenovo PCs found infected with the Superfish adware to below 1,000.

 

In a blog post announcing the addition of another Superfish clean-up tool, Microsoft's security team said that the number of infected PCs detected by its software peaked at around 60,000 on Feb. 21, slumped slightly over the next two days before falling precipitously. By Feb. 25, the daily number of infected PCs encountered by Microsoft's tools had dropped to around 3,000, sliding further over the next several days to what appeared to be less than 1,000 each day.

 

All told, Microsoft implied that about a quarter of a million Lenovo PCs were cleansed of Superfish between Feb. 20 and March 4.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...