Lenovo preinstalls man-in-the-middle adware that hijacks HTTPS traffic on new PCs

Crusty

Lifer
Sep 30, 2001
12,684
2
81
What's worse is that the private key is embedded in the software, so anybody with some technical skill can extract the key and sign any number of certs that would be trusted blindly by any computer compromised.

Great job Lenovo, I really hope there are repercussions for doing stuff like this.
 

fleshconsumed

Diamond Member
Feb 21, 2002
6,485
2,362
136
This is why I always, always do a fresh install on any laptop I buy. I always figured less bloatware was good enough reason to do a fresh install, now I can add spyware to that list.
 

mmntech

Lifer
Sep 20, 2007
17,504
12
0
It's a pretty big breach of trust on Lenovo's part, and a gaping security hole. I can't say I'm shocked given the sketchy nature of a lot of Made In China tech products. Lenovo is supposed to be a reputable brand though.

As one comment on Ars put it

"The relationship with Superfish is not financially significant,"

Translation: We were willing to throw our customers under a bus for very little money.

Since the news broke, the company has issued an apology.
http://arstechnica.com/security/201...do-enough-promises-to-wipe-superfish-off-pcs/

This is one of the reasons why I still build my own PCs and buy Mac laptops.
 

MadScientist

Platinum Member
Jul 15, 2001
2,154
47
91
Recently purchased a Lenovo Z50-70 laptop for my wife. Except for only a 4 cell battery, not a bad deal with coupon for $599. + fs. http://shop.lenovo.com/us/en/laptops/lenovo/z-series/z50/

It came in yesterday. Immediately started uninstalling bloatware, one of them was Superfish. Also cleaned the registry with Ccleaner. She uses Chrome.
Followed this procedure to delete the certificate, but it was not there.
http://arstechnica.com/security/2015/02/how-to-remove-the-superfish-malware-what-lenovo-doesnt-tell-you/

Tests:
https://filippo.io/Badfish/
https://lastpass.com/superfish/
 

seepy83

Platinum Member
Nov 12, 2003
2,132
3
71
The best advice is definitely to remove Superfish immediately. Rob Graham cracked the password for their cert yesterday (read about it here http://blog.erratasec.com/2015/02/extracting-superfish-certificate.html), and has subsequently shown how you can stand up a webserver to perform a MitM attack against clients that trust the Superfish certs. The example he used was to install a default instance of Apache that was claiming to be bankofamerica.com, and (obviously) the browser trusts the cert from superfish that's presented.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |