6 ms·
"We’re not trying to get into an argument with the security guys. They’re dealing with theoretical concerns." - Peter Hortensius I'd say that someone having cr
by packetized 12y ago
"We’re not trying to get into an argument with the security guys. They’re dealing with theoretical concerns." - Peter Hortensius
I'd say that someone having cracked out the password for the private key is a bit more than a 'theoretical' concern. This might be the most tone-deaf handling of a potential PR disaster so far this year.
- AceJohnny2 12y agoThis is cluebat level of ignorance. I want to apply the "don't ascribe to malice what can adequately be explained by ignorance" maxim, but I'm having trouble with the "adequately" here. Either they managed to live under a rock and completely ignore everything related to the Snowden revelations, or they're willfully dismissing it. Such a pity, I was looking forward to getting an X1...
- 0x0 12y agoStill trying to wipe it under carpet when the problems obviously are far from "theoretical concerns" isn't really reflecting well on Lenovo's image. It's like the opposite of damage control.
- jjoonathan 12y agoThe price of "don't ascribe to malice" is that it's trivial to exploit. The most incompetent PR department in the world can have a strict adherent on a leash and barking to their tune inside of 5 minutes. Courts of law have a good reason to hold high standards of evidence. For everyone else it's just an excuse for laziness. Not that I'm any better, I just don't insist on rationalizing it :-)
- AceJohnny2 12y agoI'm now old and cynical enough to understand/believe that the world is run with laziness as the prime heuristic (with secondary heurisitc being "don't die/maintain current level of comfort"). I agree that it's trivial to exploit, but I choose to believe that, in the general case, people/entities are lazier than they are evil. That said, laziness can be in the form of "not taking into account the externalities", which can be indistinguishable from actual malice (which I define as knowingly and/or willfully causing harm). I still think Lenovo's behaviour in this case is that form of laziness, though my comment above means I'm on the fence.
- bztzt 12y agothoughtlessness and callousness are far more common sources of evil than either incompetence or malice strictly defined. "People who don't care if I live or I die".
- AceJohnny2 12y agoI realize now I've been mixing up "incompetence" "ignorance" and "laziness". I used "ignorance" in the maxim in my first comment where it's actually "incompetence", and then discussed "laziness" in my followup comment. Sorry. FWIW, I agree with you: I put thoughtlessness and callousness fall under the laziness umbrella.
- jjoonathan 12y agoI tend to suspect you're right about this being a case of malicious laziness. Once the engineers started protesting, middle management decided it was easier to feign ignorance of the problem and push on than to come up with a more legitimate value-add. Laziness-driven, but (I suspect) also entirely malicious in the sense that if you had given anyone in the room a choice between receiving a laptop with their crapware and a laptop without, they would have chosen the latter without the slightest bit of hesitation. Then again, I may be underestimating management's ability to drink their own kool-aid.
- pekk 12y agoMy concern when making a purchase is whether the purchase will be good for me. I would definitely wipe whatever laptop I purchased, so this story is interesting and embarrassing for Lenovo but has no effect on my own purchases which are driven by what will function well for my preferences (like good Linux support and not requiring me to use a trackpad) Given the general sliminess in computer, phone and software companies, there is no "pure" option except to buy some ancient computer and never use it on the internet, like RMS. This isn't acceptable to me. I will buy what serves my own needs, and you can do whatever you want.
- AceJohnny2 12y agoIsn't Apple the least slimy in this regard? I've been eyeing Macbooks forever, but as far as I know Linux support has never been great, despite the prevalence of their hardware. System76 sells some good Linux-oriented laptops. Some of Dell's laptops are Ubuntu-certified. I had a good HP Elitebook via work about 6 years ago, but everything I've tried of theirs over the past couple years has been throw-out-the-window bad.
- dredmorbius 12y agoIf Lenovo are willing to compromise user software for some perceived corporate benefit, what's to say that they're not going to compromise hardware, firmware, bootloaders, recovery tools, etc.? I ask that from a Lenovo Thinkpad T520i, one of a half-dozen or more I've owned or used over 15+ years, and absolutely my preferred mobile hardware over that period.
- rodgerd 12y ago> This might be the most tone-deaf handling of a potential PR disaster so far this year. It's appealing to a common and sucessful strategy of dismissing the concerns of experts as the irrelevant waffling of a bunch of eggheads disconnected from reality. Lenovo are hoping their user base will pop "security researchers" in the same bucket as beachfront property owning SUV drivers place "climate scientists".
- reitanqild 12y agoWhat about private-jet-plane-flying-climate-scientists and (especially) worriers?
- takluyver 12y ago> This might be the most tone-deaf handling of a potential PR disaster so far this year. I think you're assuming that the broader public shares the indignation of HN about this. On mainstream news sites, it's down under the 'technology' heading. It sounds like Lenovo is scrambling a fix that will remove the certificate. If that's out in the next day or two and they have a way to get most affected users to apply it, probably hardly anyone will get clearly 'hacked'. They'll keep playing the 'honest mistake' card, and it will mostly blow over.
- ZanyProgrammer 12y agoLess technically inclined people will still buy Lenovo's lower range products, and I'm sure businesses will do the enterprise thing and continue to buy Lenovo, since they tend to be the definition of ossified. But what about power users? I think Lenovo (and ThinkPads in general) have a reputation as the power user computer for Windows and Linux users. Not the biggest hit to be sure, and nothing to get the attention of CNN, but surely Lenovo will lose a certain segment of power users.
- takluyver 12y agoThey're losing favour among a - probably fairly small - segment of users. But they're probably calculating that they'd lose much more customer confidence by admitting that it's a big problem, especially before they've got a fix out. In a couple of days, they might be much more contrite about this. But today, the PR department's number one job is to keep it from becoming a big story in mainstream media.
- xerphn 12y agoThis says a good deal about your company's priorities. You say you do due diligence to make sure the software you include is secure... yet you miss on such blatant vulnerabilities. "Not doing enough" only scrapes the surface.
- fpgeek 12y agoThis just occurred to me: Lenovo is a Chinese company and this broke right at the start of the Chinese Lunar New Year (a Christmas-sized or arguably bigger holiday in Chinese culture). Obviously I can't prove this is having an impact, but it wouldn't shock me to find out that this contributed to the amazing PR tone-deafness and incompetence of their response so far. Of course, that wouldn't excuse any of the terrible decisions made earlier, but it would be an interesting wrinkle from the perspective of assessing their crisis-management.