Results 1 to 4 of 4

Thread: Superfish: Lenovo preinstalled dangerous Adware and MITM software

  1. #1
    Senior Member
    Join Date
    Jan 2004
    Location
    Cambridge
    Posts
    283
    Thanks
    13
    Thanked
    24 times in 23 posts
    • timread's system
      • Motherboard:
      • MSI B450 Tomahawk Max
      • CPU:
      • AMD Ryzen 5 3600
      • Memory:
      • 16GB (2x8GB) Corsair DDR4 Vengeance LPX
      • Storage:
      • 1x WD Blue SN550 500GB M.2 NVMe SSD, , 1x Crucial MX500 1TB SSD, 2x WD 1TB HDD in RAID1
      • Graphics card(s):
      • Gigabyte GeForce GTX 1660 Ti WINDFORCE OC 6G
      • PSU:
      • EVGA SuperNOVA 750W Gold Gen2
      • Case:
      • Fractal Design Define R3 Arctic White
      • Operating System:
      • Windows 10 Pro
      • Monitor(s):
      • AOC 2590 G4, Dell U2412M
      • Internet:
      • VirginMedia

    Superfish: Lenovo preinstalled dangerous Adware and MITM software

    Surprised not to see a mention of it yet in these forums... Lenovo has admitted preinstalling dangerous adware on many consumer machines sold between September and December 2014, called Superfish. Ostensibly it's just ad insertion crapware. However, the software installs a Root CA Certificate and acts as man-in-the-middle proxy, meaning that it can inject itself into your online banking and other HTTPS website usage. Better still, the root CA certificate only used 1024-bit encryption and the certificate password has already been cracked.

    Lenovo don't seem to understand just how major a screw up this is, yet.

    There's more information here:
    http://www.kb.cert.org/vuls/id/529496
    http://www.theregister.co.uk/2015/02...erfish_killer/ (this article also contains a list of the Lenovo models affected)
    http://blog.erratasec.com/2015/02/ex...rtificate.html

    Check if your Lenovo is one of the ones affected by visiting this website:
    https://filippo.io/Badfish/ (this is a genuine link, listed in the CERT article linked above - visit it via that article if you don't trust me)

  2. #2
    Registered+
    Join Date
    Mar 2015
    Location
    peterborough
    Posts
    13
    Thanks
    0
    Thanked
    0 times in 0 posts
    • russelllongy's system
      • Motherboard:
      • asrock h81-hds matx
      • CPU:
      • intel pentium g3258 @ 4.8ghz
      • Memory:
      • 8gb kingston savage 1600mhz cl9
      • Storage:
      • 120gb sandisk ssd, 1tb wd blue for games
      • Graphics card(s):
      • asus gtx 980
      • PSU:
      • corsair cx500
      • Case:
      • corsair carbide spec 03
      • Operating System:
      • windows 8.1 pro
      • Monitor(s):
      • samsung syncmaster 26 inch 1080p
      • Internet:
      • talktalk 76mb fibre

    Re: Superfish: Lenovo preinstalled dangerous Adware and MITM software

    i looked at gettin a lenovo laptop 2 days ago and this issue stopped me from buying it

  3. #3
    Registered+
    Join Date
    Oct 2015
    Posts
    25
    Thanks
    0
    Thanked
    0 times in 0 posts

    Re: Superfish: Lenovo preinstalled dangerous Adware and MITM software

    This is all true, but there are a couple of superfish removal tools readily available even directly from Lenovo. Apart from that I prefer reinstalling windows as soon as I can with new pcs, especially with the windows 10 upgrade thing.

    Also if you upgrade to windows 10 but don't keep the old files you can allegedly get rid of it...

  4. #4
    Registered+
    Join Date
    Dec 2012
    Location
    Manchester
    Posts
    21
    Thanks
    0
    Thanked
    2 times in 2 posts
    • dotdrew's system
      • Motherboard:
      • P8P67 Deluxe
      • CPU:
      • 2600K
      • Memory:
      • 8GB XMS3 2000MHz
      • Storage:
      • 256GB C300 SSD, 2 x 1TB HDD
      • Graphics card(s):
      • EVGA GTX 580 SC
      • PSU:
      • Seasonic P1000W
      • Case:
      • FT02
      • Operating System:
      • Windows 8
      • Monitor(s):
      • Hazro HZ27WC 2560x1440
      • Internet:
      • 50Mbps

    Re: Superfish: Lenovo preinstalled dangerous Adware and MITM software

    I was recently looking at Lenovo All-In-Ones for my parents, thanks for reminding me of this, I'll have to do some research into other brands as well now haha.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •