PDA

View Full Version : Lenovo PCs ship with man-in-the-middle adware that breaks HTTPS connections - Ars T.



blackbird34
February 19th, 2015, 03:54 PM
Lenovo is selling computers that come preinstalled with adware that hijacks encrypted Web sessions and may make users vulnerable to HTTPS man-in-the-middle attacks that are trivial for attackers to carry out, security researchers said.
(...)


http://arstechnica.com/security/2015/02/lenovo-pcs-ship-with-man-in-the-middle-adware-that-breaks-https-connections/?comments=1&start=80

The comments section is in uproar.

grahammechanical
February 19th, 2015, 08:54 PM
This is how the BBC published the news

http://www.bbc.co.uk/news/technology-31533028

If that is the same superfish as this superfish than this matter could be much, much worse.

http://www.home.superfish.com/#!partners/c1qiz

People may be installing apps using this technology.

Regards.

Linuxratty
February 20th, 2015, 06:02 PM
I'd love to know why they think it's perfectly ok to do this sort of thing. it reminds me of Sony's rootkit.

blackbird34
February 23rd, 2015, 10:39 PM
More Ars coverage, it looks like this is a potentially massive story with lots of companies involved... including Comodo

http://arstechnica.com/security/2015/02/security-software-found-using-superfish-style-code-as-attacks-get-simpler/

Hexxus
February 23rd, 2015, 11:05 PM
I just read on Facebook - all over the place that there is a law-suit over it now to Lenovo... not totally surprised. I mean, you take money and don't have it vetted out? Kinda funky if you ask me...

CantankRus
February 24th, 2015, 02:59 AM
I just read on Facebook - all over the place that there is a law-suit over it now to Lenovo... not totally surprised. I mean, you take money and don't have it vetted out? Kinda funky if you ask me...
Not surprising.... US lawyers don't miss an opportunity for a class action.

Linuxratty
February 24th, 2015, 02:37 PM
It never ceases to amaze me what big companies think they can get away with.

mastablasta
February 24th, 2015, 03:56 PM
More Ars coverage, it looks like this is a potentially massive story with lots of companies involved... including Comodo


Comodo issue seems to have been limited to a certain version, and it was already patched in the same day. as per their comment it was an error in a library or something. anyway not something they intended to happen is what they say.

hmm... the thing is why do they add some many things for example to their firewall.... you now have virus scanner, virtual desktop, firewall... and many other things in Comodo firewall.