6 ms·
I'm always surprised that Lenovo use in the enterprise space didn't take a hit after all this came to light. I would have thought competitors like Dell and HPE
by lamlam 8y ago
I'm always surprised that Lenovo use in the enterprise space didn't take a hit after all this came to light. I would have thought competitors like Dell and HPE would have used that opportunity to disparage Lenovo.
- 35345dfgd 8y agoNo enterprise is using the base windows image that came from Lenovo with the superfish malware. They all build their own standard operating environment image that would not include the Lenovo bloatware. I would be surprised if Lenovo enterprises even realized they were shipping this way and have no reason to react negatively. Their competitors also live in glass houses and so cannot throw stones.
- larkeith 8y agoLenovo is known to install rootkits in their devices [1], which an OS image will not prevent. Do you have a citation for Lenovo's competitors installing comparably vulnerable malware? [1] https://threatpost.com/lenovo-hit-with-criticism-over-second-rootkit-like-utility/114261/ https://threatpost.com/lenovo-hit-with-criticism-over-second...
- lamlam 8y agoSo yes, in a normal case, one would expect to be safe because they are using their own built image. But Lenovo went much further than simply installing crapware, they added a firmware that updates files on startup in the OS to ensure that they had a way to install whatever they wanted onto your system [1]. [1] https://www.theregister.co.uk/2015/08/12/lenovo_firmware_nasty/ https://www.theregister.co.uk/2015/08/12/lenovo_firmware_nas...
- lamlam 8y agoTo add to this, while the Superfish issue only affected their consumer laptop lines (e.g. IdeaPad), the LSE issue was found on their enterprise lineup (e.g. ThinkPad).
- 35345dfgd 8y agoWasn't aware of the LSE issue on enterprise models! This is a feature that would get enterprises angry if it messes with the OS by injecting bins full of vulnerabilities from BIOS. Gross!
- zdy132 8y agoOnly a quick read, but both the lenovo pressroom and the guardian stated the thinkpads were not affected. pressroom: https://news.lenovo.com/pressroom/press-releases/lenovo-statement-on-lenovo-service-engine-lse-bios.htm https://news.lenovo.com/pressroom/press-releases/lenovo-stat... the guardian: https://www.theguardian.com/technology/2015/aug/14/lenovo-service-engine-pre-installed-security-superfish https://www.theguardian.com/technology/2015/aug/14/lenovo-se...
- Rjevski 8y agoNo enterprise would use the factory image, but a lot of small businesses would and they were put at risk as a result. We can of course say they shouldn't have trusted it, but honestly, should it be normal to expect the manufacturer of the machine to be malicious? Not to mention the other commenters pointed out that they used the firmware to reinstall the malware even on otherwise clean images, so even enterprises could've been at risk.
- cbzoiav 8y agoIf you don't trust the manufacturer then the OS is the least of your worries. You can't trust the hardware, microcode or firmware either.
- closeparen 8y agoLenovo is behaving as an attacker against its customers. That sophisticated customers had defenses for this particular attack is irrelevant. Imagine if iPhones started trying dictionary attacks against their peers on WiFi networks. Would you shrug it off and continue buying Apple products because you trust your password complexity rules? It’s great that the countermeasures worked this time, but Lenovo is still your adversary. They deserve the same response as any other insider who tries to MITM your traffic: immediate termination, a thorough search for any remaining implants, and an FBI battering ram through their door.
- hannob 8y agoI mean Dell took the opportunity to do almost exactly the same thing shortly afterwards.
- jammygit 8y agoDell did it too. https://arstechnica.com/information-technology/2015/11/dell-does-superfish-ships-pcs-with-self-signed-root-certificates/ https://arstechnica.com/information-technology/2015/11/dell-... Apparently hp also https://www.computerworld.com/article/3238512/microsoft-windows/hp-stealthily-installs-new-spyware-called-hp-touchpoint-analytics-client.html https://www.computerworld.com/article/3238512/microsoft-wind...
- lamlam 8y agoVery interesting! I had not heard of these incidences.