Announcement

Collapse
No announcement yet.

Check your Lenovo!!!

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Check your Lenovo!!!

    If you own a Lenovo you have some checking to do.
    WOW. Will never buy one again.


    ...
    To recap: Since at least September, Lenovo has been shipping OEM Windows laptops preloaded with Superfish “adware,” which would rudely inject its own shopping results into your browser when you searched on Google, Amazon, and other websites. This sort of behavior is associated more with spyware than with factory-shipped operating-system installs, and by itself would be a new low for Lenovo. But Superfish is more than just pesky. It’s the most virulent, evil adware you could find.

    By installing a single self-signed root certificate (trust me: That’s really bad) across all of Lenovo’s affected machines, Superfish intentionally pokes a gigantic hole into your browser security and allows anyone on your Wi-Fi network to hijack your browser silently and collect your bank credentials, passwords, and anything else you might conceivably type there. As Errata Security’s Robert Graham put it, “I can intercept the encrypted communications of SuperFish’s victims (people with Lenovo laptops) while hanging out near them at a cafe wifi hotspot.” If you have a Lenovo laptop that has Superfish on it (try Filippo Valsorda’s Superfish test to see), I would advise nothing short of wiping the entire machine and installing vanilla Windows—not Lenovo’s Windows. Then change all of your passwords.
    ...
    More info: http://marcrogers.org/2015/02/19/lenovo-installs-adware-on-customer-laptops-and-compromises-all-ssl/
    Last edited by cjolley; 20 February 2015, 07:41.
    Chuck
    秋音的爸爸

  • #2
    Just did, thanks for that. Bought a Lenovo for my youngest daughter a while back. Actually a great machine for the price. Also, it came with the W7 upgrade from W8.1 pre-installed. Think it was a bit of an older model and hence not infected. I would still buy one though. Prefer clean installs anyway. Come to think of it, my Asus lappy and my wife's two Dell PCs..all clean installs because I hate the way they do it. Now there is an additional reason I guess.
    Join MURCs Distributed Computing effort for Rosetta@Home and help fight Alzheimers, Cancer, Mad Cow disease and rising oil prices.
    [...]the pervading principle and abiding test of good breeding is the requirement of a substantial and patent waste of time. - Veblen

    Comment


    • #3
      There's no Superfish on my Thinkpad X240.

      Comment


      • #4
        The underlying tech may be more wide spread than previously thought:
        So, as people have started turning over stones, looking to see how common these Komodia certificates are, some surprising (and depressing) things are beginning to surface. It does appear that Komod…
        Chuck
        秋音的爸爸

        Comment


        • #5
          I'm running Windows 10 on T540p so no worries here. The start menu and all the modern apps died but that's not problem as I can right click and search for program from start menu and i copied old calc.exe from another machine (that was only really needed modern app.)

          Comment


          • #6
            I think this particular vulnerability would would work on any OS that uses trusted certificates. I wonder if any other software install certs using the Komodia API?
            Chuck
            秋音的爸爸

            Comment


            • #7
              Apparantly yes, http://marcrogers.org/2015/02/19/wil...re-everywhere/.
              Join MURCs Distributed Computing effort for Rosetta@Home and help fight Alzheimers, Cancer, Mad Cow disease and rising oil prices.
              [...]the pervading principle and abiding test of good breeding is the requirement of a substantial and patent waste of time. - Veblen

              Comment

              Working...
              X