6 ms·
"We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns." Seriously?!
by pcora 12y ago
"We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns."
Seriously?!
- TwoBit 12y agoAnybody can MITM secure connections these computers make, right?
- rockdoe 12y agoYes.
- SixSigma 12y agoAnd present any HTTPS cert of their choosing to any compromised visitors e.g https://b4nk0famer1ca.com/ https://b4nk0famer1ca.com/
- tomp 12y agoHm... I'm pretty sure that if you can actually MITM their connection (i.e. you can intercept and modify the packages, e.g. by setting up a rogue Wi-Fi hotspot), you can also fake the DNS and/or IP addresses, so you shouldn't have a problem compromising visitors of https://bankofamerica.com https://bankofamerica.com.
- Xylakant 12y agoyou don't need to fake IPs or DNS requests - if you have MITMed their connection then all their traffic flows through your machine and you can present whatever content you desire on any domain.
- SixSigma 12y agoThe point being that you don't have to MITM their connection. The private key is in the wild, you can sign a cert and host it anywhere on the internet. Any visitors who have that see that cert signed by that root cert will say "yep, fine, go ahead". So then you spam the world with "Important message from Lenovo" and hope they click on https://len0v0.com https://len0v0.com and install your important update
- methou 12y agoFirst stage - denial.
- morganvachon 12y agoNot even a hint of an admission on the certificate issue, I'm not surprised. If they admit they knew about the root certificate or even acknowledge its existence after the discovery, they could open themselves up to legal liability if someone's bank account or identity is compromised. This really sucks because I used to recommend Lenovo workstations and ThinkPad laptops to people; it really is good hardware at a decent price. I know this certificate/spyware issue was only on the consumer side, but it stains their entire reputation as far as I'm concerned. When my wife's Lenovo IdeaPad finally dies, we're not going to get another Lenovo like we planned.
- shaneg 12y agoThey actually reference the root certificate in their removal instructions: "Uninstalling Superfish Visual Discovery Go to Control Panel > Uninstall a Program Select Visual Discovery > Uninstall Superfish will be removed from Program Files and Program Data directories, files in user directory will stay intact for the privacy reason. Registry entry and root certificate will remain as well. The Superfish service will stop working as soon as it is uninstalled via above process, and following reboot." http://forums.lenovo.com/t5/Lenovo-P-Y-and-Z-series/Removal-Instructions-for-VisualDiscovery-Superfish-application/ta-p/2029206 http://forums.lenovo.com/t5/Lenovo-P-Y-and-Z-series/Removal-...
- TeMPOraL 12y agoSo they're basically telling you how to get rid of ads and call it solved, while still leaving you vulnerable to getting robbed by any script kiddie that gets his hands on the certificate key?
- HackinOut 12y ago"This article will be updated with additional instructions on clean up of deactivated files and removal of certificate shortly." This was just edited, here is the post before that: https://web.archive.org/web/20150219151726/http://forums.lenovo.com/t5/Lenovo-P-Y-and-Z-series/Removal-Instructions-for-VisualDiscovery-Superfish-application/ta-p/2029206 https://web.archive.org/web/20150219151726/http://forums.len...
- notacoward 12y agoI had the same reaction. If that's true, it's almost more worrying than if they admitted their complicity. What other gaping holes might someone that dumb about security have left open? More likely, it's just something they have to say for liability reasons. If they admit that it's a problem, every lawsuit against them gets much easier and is likely to yield higher damages. In a way, that same legal system often lauded as an alternative to regulation forces them to say something that's not true.
- wvenable 12y agoI expected that quote, but this one is even more off the rocker: "The relationship with Superfish is not financially significant; our goal was to enhance the experience for users." Right.