Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

How Lenovo's dangerous Superfish adware put its customers at risk
Consumer Reports ^ | 2-20-15 | Donna Tapellini

Posted on 02/20/2015 1:19:16 PM PST by smokingfrog

The Internet is lighting up with warnings about Superfish, an adware program that came preinstalled on many Lenovo laptops in the past six months. Like a lot of the bloatware that comes on new computers, Superfish exists to help push advertising, not to serve any real consumer need. That would be annoying enough, but Superfish seriously undermines the user's safety, according to many security experts.

Superfish is a piece of third-party software that Lenovo installed to, as it says in its apology to consumers, “enhance the shopping experience.” That means it's meant to help advertisers target potential customers. But security experts say the software makes it easy for cybercriminals to intercept your data as it travels from your computer out to the Internet.

That’s because of the way Superfish deals with what’s called a root certificate. These certificates tell your computer what content to trust when you go to a secure site. The problem is, in order to place ads, Superfish installs its own root certificate that allows it to intercept and unencrypt your encrypted communications. Even if Lenovo's paying customers don't mind Superfish intruding in that way, they should be concerned because the software opens their communications to a malicious man-in-the-middle attack by hackers.

“What they would get is everything passing out of your machine—every password, every bank-account number, every e-mail,” said Professor Fred Cate, founding director and senior fellow at the Center for Applied Cybersecurity Research at Indiana University’s Maurer School of Law.

(Excerpt) Read more at consumerreports.org ...


TOPICS: News/Current Events; Technical
KEYWORDS: adware; computersecurity; lenovo; maleware; malware
Navigation: use the links below to view more comments.
first 1-2021-32 next last
Cross Lenovo computers off your shopping list.
1 posted on 02/20/2015 1:19:16 PM PST by smokingfrog
[ Post Reply | Private Reply | View Replies]

To: smokingfrog

Delete junkware from a new computer and update your protection.


2 posted on 02/20/2015 1:20:30 PM PST by goldstategop (In Memory Of A Dearly Beloved Friend Who Lives In My Heart Forever)
[ Post Reply | Private Reply | To 1 | View Replies]

To: smokingfrog

Most computers come with bloatware , it’s your own fault if never clean it out


3 posted on 02/20/2015 1:21:58 PM PST by molson209 (Blank)
[ Post Reply | Private Reply | To 1 | View Replies]

To: molson209

I have a Lenovo Thinkpad.

They’re as top notch as those made by IBM.

Love it.


4 posted on 02/20/2015 1:23:24 PM PST by goldstategop (In Memory Of A Dearly Beloved Friend Who Lives In My Heart Forever)
[ Post Reply | Private Reply | To 3 | View Replies]

To: molson209
Most computers come with bloatware , it’s your own fault if never clean it out

One expects bloatware, but not a root kit!

5 posted on 02/20/2015 1:23:41 PM PST by Pearls Before Swine
[ Post Reply | Private Reply | To 3 | View Replies]

To: Pearls Before Swine

Uninstall it and its gone.

My rule of thumb is unless they are computer company utilities, I delete what’s pre-installed and install my own software.


6 posted on 02/20/2015 1:25:05 PM PST by goldstategop (In Memory Of A Dearly Beloved Friend Who Lives In My Heart Forever)
[ Post Reply | Private Reply | To 5 | View Replies]

To: smokingfrog

Here is the Lastpass site that tests for it.

https://lastpass.com/superfish/


7 posted on 02/20/2015 1:26:10 PM PST by ansel12 (Palin--Mr President, the only thing that stops a bad guy with a nuke is a good guy with a nuke.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: goldstategop

I like STOPzilla, has never failed me.


8 posted on 02/20/2015 1:26:51 PM PST by boomop1 (Term limits is the only source of change.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: ansel12

Seriously, that’s why I have Adblock Plus. Its free and it blocks malware domains too as well getting rid of nearly all adware - great for watching free movies.


9 posted on 02/20/2015 1:28:10 PM PST by goldstategop (In Memory Of A Dearly Beloved Friend Who Lives In My Heart Forever)
[ Post Reply | Private Reply | To 7 | View Replies]

To: smokingfrog
This is a serious screwup by Lenovo. They make super hardware but be careful of the crapware: software a computer manufacturer loads on machines they sell. The software supplier pays the manufacturer for the "privilege" of being loaded on the computer.

If you have a Lenovo computer, you can check here to see if you have the Superfish malware and, if you do, get removal instructions.

10 posted on 02/20/2015 1:29:53 PM PST by upchuck (The current Federal Governent is what the Founding Fathers tried to prevent. WAKE UP!! Amendment V.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: goldstategop

Laptops need to be well built.
Apple
Lenovo

These are about the only ones I trust anymore.


11 posted on 02/20/2015 1:32:03 PM PST by Zathras
[ Post Reply | Private Reply | To 4 | View Replies]

To: goldstategop

This is an actual program that is pre loaded on their computers.


12 posted on 02/20/2015 1:42:24 PM PST by ansel12 (Palin--Mr President, the only thing that stops a bad guy with a nuke is a good guy with a nuke.)
[ Post Reply | Private Reply | To 9 | View Replies]

To: ansel12

Or build your own pc.

sent from my killer Linux box, running Cinnamon Mint 17.1


13 posted on 02/20/2015 1:48:19 PM PST by bicyclerepair (Ft. Lauderdale FL (zombie land). TERM LIMITS ... TERM LIMITS)
[ Post Reply | Private Reply | To 12 | View Replies]

To: bicyclerepair

That wouldn’t work if you wanted a Lenovo.


14 posted on 02/20/2015 1:49:42 PM PST by ansel12 (Palin--Mr President, the only thing that stops a bad guy with a nuke is a good guy with a nuke.)
[ Post Reply | Private Reply | To 13 | View Replies]

To: smokingfrog

About 3 years ago HP won the contract to supply NASA computers. The ACES contract. They started rolling out Lenovo desktops. I wondered why NASA, a government agency, would allow a foreign owned company to supply computers.

I was told by an IT person that one day while they had 25 computers setup & installing the NASA client version of Windows that an IT security guy came running into the room and yanking network cables out of the computers.

One of the computers, OUT OF THE BOX, started uploading to a website in China. From that day forward, no more Lenovos were installed.


15 posted on 02/20/2015 2:00:30 PM PST by Bryan24 (When in doubt, move to the right..........)
[ Post Reply | Private Reply | To 1 | View Replies]

To: upchuck

“They make super hardware.”

Their Lenovo M81 Series would not recognize National Instruments PXI Controller Cards. It is my professional opinion they are cheap pieces of computer garbage.


16 posted on 02/20/2015 2:04:08 PM PST by Bryan24 (When in doubt, move to the right..........)
[ Post Reply | Private Reply | To 10 | View Replies]

To: smokingfrog

I have an IBM 3000 N100.

The first thing I did when I bought it: Wiped clean the hard drive, and installed Windows from media I already have.


17 posted on 02/20/2015 2:22:46 PM PST by __rvx86 (Rafael Cruz Jr: soon to be the first conservative, Latino President of the U.S. ¡Si se puede!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: smokingfrog

Thank you for posting this! I have a new lenovo and just removed the threat.


18 posted on 02/20/2015 2:26:52 PM PST by BillyBonebrake
[ Post Reply | Private Reply | To 1 | View Replies]

To: Zathras

I heard Asus laptops were pretty good.

Opinions? I’m kind of in the market for a new one, but not willing to plunk down too much for an Apple. Just need pretty basic computer stuff.


19 posted on 02/20/2015 2:36:57 PM PST by smokingfrog ( sleep with one eye open (<o> ---)
[ Post Reply | Private Reply | To 11 | View Replies]

To: upchuck

Think twice the next time you click on that “AGREE” button!


20 posted on 02/20/2015 2:37:45 PM PST by smokingfrog ( sleep with one eye open (<o> ---)
[ Post Reply | Private Reply | To 10 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-32 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson