Lenovo apologizes for pre-loaded insecure adware "Superfish"

by
in microsoft on (#3GD2)
Lenovo, the world's largest PC manufacturer, has apologized for security flaws in the malware they pre-install on consumer laptops, and attempted to issue instructions on how to fix a flaw that fatally compromised user security. The company was forced to issue a second set of instructions after security experts said that following its first set would do nothing to patch up the security holes the adware created. But even the second set is "incomplete", according to researchers, and leaves users of the popular Firefox browser vulnerable.

Sadly, while apologizing for the security hole the software opens up, they are standing by their pre-installed malware, saying "this tool was to help enhance our users' shopping experience". The software bombarded affected users with pop-up adverts and injected more ads into Google searches. Security experts say it also left a gaping security hole on every computer, in the form of a self-signed root certificate. That certificate was used by the software to inject adverts even into encrypted websites, but its presence has the side-effect of making affected Lenovo computers trivially easy to hack with a "man in the middle" (MITM) attack, in which a hacker uses the certificate to pretend to be a trusted website, such as a bank or e-commerce site. The "man in the middle" can then steal information passed over the internet, even while the user believes they are safely browsing with encryption turned on. Filippo Valsorda, who created the Badfish tool for determining if a computer is affected by the software, has offered instructions for how to remove it from that browser as well.

See ya (Score: 1)

by zafiro17@pipedot.org on 2015-02-25 16:50 (#3T81)

No worries Lenovo, I accept your apology. But I will also never again consider one of your machines. I need to trust my hardware manufacturer, and now thanks to your ass-hattedness, I no longer trust you.

Whichever dumbass middle manager thought this would be a great revenue earner for you should be made to fall on his own sword and then fed to a pool of sharks. The trust of your clients is worth more than a little ad money. How could you all have been so stupid?

Anyway, enjoy irrelevance. Your brand is tarnished. Maybe you and Sony should get together and have a party? You're made for each other - you both screwed the pooch in the same way.
Post Comment
Subject
Comment
Captcha
What is seventeen thousand and nine as a number?