6 ms·
Question for the more legally-minded among us: Can Lenovo face consequences over this? I mean, they deliberately crippled the security systems of their consumer
by Kronopath 12y ago
Question for the more legally-minded among us: Can Lenovo face consequences over this? I mean, they deliberately crippled the security systems of their consumer goods, presumably without properly notifying their customers. That sounds like the kind of thing a company could, or should, get sued for.
- compbio 12y agoDutch IT lawyers [1] say that Lenovo could be breaching European and Dutch Law. More specifically the "cookie law" which says that explicit permission is needed to change and read data from a user's computer (Lenovo never asked explicit permission). I also hear mentions of breaching the "computer intrusion" law (classifying this as a hack) and even the "communications tapping" law (Lenovo is not licensed to MitM your connections). I do not think a EU class-action or private citizen lawsuit will follow, but perhaps the official institutions can hand out a big fine. However, if Lenovo MitM'ed your connections and you can prove that, that would in principle be enough to get this case in front of a tort judge. [1] http://tweakers.net/nieuws/101472/lenovo-overtreedt-wet-met-voorgeinstalleerde-malware.html http://tweakers.net/nieuws/101472/lenovo-overtreedt-wet-met-... (lang:nl)
- pbhjpbhj 12y agoI don't know Dutch law but I'm interested you say "tort judge" - unauthorised access to computing systems is made a crime in EU. It should be a criminal prosecution.
- jfoutz 12y agoDidn't they come that way? It's not like they secretly snuck into your house and changed your computer. They sold something broken. It's the difference between going to your house and breaking the latch on your window, vs selling you a window that won't latch.
- DennisP 12y agoIf I sell you a window that only appears to latch, and then come by later and rob your house, I might face criminal charges. Lenovo didn't just sell something with broken security. It purposely broke the security, and profited from it.
- deleted 12y ago[deleted]
- belorn 12y agoAdware is not a broken product, it is an illegal scheme to earn profit on other peoples hardware by deliberate deception. Did they inform their customers in advertisements, in the stores, or in any way that sold devices was being used by Lenovo after sale? Were there a meeting of minds where customers agreed to have their traffic MiTM and have advertisement of Lenovo choice on their device in return for fair compensation? That could have made it legal, but as it stand, no aspects of consumer protection laws, advertisement laws, contract laws, computer crime laws, or data protection laws seemed to have be followed. They secretly snuck into peoples private property, used a backdoor, and earned profits doing so. They didn't tell anyone for obvious reasons. Had it been a one-man company doing this, then that person would be facing jail time.
- xorcist 12y agoLenovo actively circumvented your security and sold access to your computer to Superfish. If you want to compare it to windows, it's like a security door salesman who sells extra keys to organized crime on the side.
- rmc 12y agoI'm sure they might claim that the user agreed to it, but it's important to remember that EU Data Protection law places limits on what people can agree to. You can store person data if it's proportionate for a cause. MitMing all SSL connections? No way is that proportionate.
- jjarmoc 12y agoIANAL; In the Lenovo case, probably not. But in the case of an employer-provided system and network intended for business purposes which performs SSL interception for security and data leak prevention? I think it can clearly be considered reasonable for the company to do that, and the user's expectation of privacy is significantly different. I do feel it's important that Acceptable Use Policies, Employee handbooks, etc. disclose the activity though.
- Drakim 12y agoDefinitely, but no way Lenovo can even get close to the same sort of justification. It's reasonable that my workplace monitor and manage how their network bandwidth is being used. It's not reasonable that Lenovo gets to spy on my specifically encrypted traffic just because I bought a computer from them for personal use.
- ptaipale 12y agoIn this case, Lenovo hardly is spying or even interested. The bad thing is they are a) selling capability to advertise to you, without your real consent, and b) when the do it, the implementation is so horribly broken that it exposes end users to be exploited by just about anyone. I see little malice, I see a lot of incompetence and outright, unforgivable stupidity. This opens door to the malice of others.
- TwoBit 12y agoWell anybody can file a class action lawsuit.
- rlpb 12y agoAIUI, the only people who could claim damages in a civil suit are ones that could demonstrate actual costs as a consequence for Lenovo's action. Maybe the cost of a security audit required as a consequence of this issue might qualify - I don't know. But there would have to be actual costs involved.
- Jolijn 12y ago"AIUI"? What's that now? Ok, googled it, wait for it... "As I understand it". Whew!
- coldpie 12y agoThank you. IRDUTPOTOA (I really don't understand the point of these obscure acronyms).
- Afton 12y agoThat's because you find them obscure. If your community used them more frequently you would just read them in place, like people do with IANAL, LGTM, AFAIK, etc. Incidentally, I didn't understand this one, but I don't blame OP (oops, I mean 'original poster') for misunderstanding the linguistic norms of HN (hacker news).
- remarkEon 12y agoThe demonstration of harm is what would be key in this case. Showing that things have the potential to cause harm often isn't enough.
- pbhjpbhj 12y agoIn UK, as I understand it, unauthorised access to computers and networks/communications under the Computer Misuse Act is a strict liability situation: you only have to do it to break the law, no harm needs to be shown. MitM-ing my connection would be unauthorised access. It's a crime.
- chippy 12y agoShould there be some form in intention, I wonder?
- tankenmate 12y agoAccording to the CMA [0]; The offence of unauthorised access requires proof of two mens rea elements, (see section 4 CMA): (1) there must be knowledge that the intended access was unauthorised; and (2) there must have been an intention to obtain information about a program or data held in a computer - section 1(2) CMA. [0] http://www.cps.gov.uk/legal/a_to_c/computer_misuse_act_1990/ http://www.cps.gov.uk/legal/a_to_c/computer_misuse_act_1990/
- pbhjpbhj 12y agoSee also http://www.legislation.gov.uk/ukpga/1990/18 http://www.legislation.gov.uk/ukpga/1990/18 - the current unauthorised intercept of data, installation of a MitM system appears to be an offence under inter alia Section 1, 2 and 3 separately.
- compbio 12y agoThere is also negligence. Like in the original case [1] where a woman got ill and suffered emotional distress after drinking bottled ginger beer with a decomposing snail in it. Even though the manufacturer had no intent to sell "snail beer" -- a consumer has a trust relationship with them: in exchange for money they can reasonably expect the manufacturer to take enough care not to bug them. [1] http://en.wikipedia.org/wiki/Donoghue_v_Stevenson http://en.wikipedia.org/wiki/Donoghue_v_Stevenson "it was reasonably foreseeable that failure to ensure the product's safety would lead to harm of consumers."
- robin_reala 12y ago@JustinBrookman just linked[0] to this FTC ruling against HTC in a similar case in 2013: http://www.ftc.gov/news-events/press-releases/2013/02/htc-america-settles-ftc-charges-it-failed-secure-millions-mobile http://www.ftc.gov/news-events/press-releases/2013/02/htc-am... Choice quote: The settlement requires HTC America to develop and release software patches to fix vulnerabilities found in millions of HTC devices. In addition, the settlement requires HTC America to establish a comprehensive security program designed to address security risks during the development of HTC devices and to undergo independent security assessments every other year for the next 20 years. [0] http://twitter.com/JustinBrookman/status/568466666771910657 http://twitter.com/JustinBrookman/status/568466666771910657
- patcheudor 12y agoCrippled isn't the word. They broke browser cryptography. The Superfish MitM proxy on the host is validating any cert it gets, even patently bogus ones. As a result it's possible for a networked MitM who is actively going after SSL/TLS traffic to see all traffic with no need to have the Superfish private. Here's a screenshot of what their MitM proxy provides back to the browser for a compromised connection to Bank of America: https://defaultstore.com/four.png https://defaultstore.com/four.png Note that my MitM proxy cert is one gen'd with OpenSSL and is not the Superfish private! While it's cool that the private can be extracted, given the failure of the Superfish software to properly validate the public in the SSL/TLS handshake, the Superfish private isn't something a bad guy needs to get in the middle of encrypted traffic.
- rjurney 12y agoOnce Lenovo was bought by a chinese company... didn't everyone kind of assume the state of China would use this opportunity to do what the NSA does for American hardware? The extent of the NSA's actions weren't known at the time, but you had to assume China would be less bound by restrictions.