Author Topic: Lenovo superfish scandel  (Read 823 times)

0 Members and 1 Guest are viewing this topic.

Offline Axon

  • VIP
  • King
  • *
  • Posts: 2047
  • Cookies: 319
    • View Profile
Lenovo superfish scandel
« on: February 21, 2015, 10:59:03 pm »
Lenovo is selling computers that come preinstalled with adware that hijacks encrypted Web sessions and may make users vulnerable to HTTPS man-in-the-middle attacks that are trivial for attackers to carry out, security researchers said.
http://arstechnica.com/security/2015/02/lenovo-pcs-ship-with-man-in-the-middle-adware-that-breaks-https-connections/

Rob Graham, CEO of security firm Errata Security, has cracked the cryptographic key encrypting the Superfish certificate. That means anyone can now use the private key to launch man-in-the-middle HTTPS attacks that won't be detected by machines that have the certificate installed.
http://blog.erratasec.com/2015/02/extracting-superfish-certificate.html#.VOX5Ky57RqE

This is crazy, now we can't even trust the laptops manufacturers!! I wonder if other companies have done the same but are still not discovered.

Lesson learned: Do Not Trust The Chinese.

« Last Edit: February 21, 2015, 11:00:07 pm by Axon »

Offline d4rkcat

  • Knight
  • **
  • Posts: 287
  • Cookies: 115
  • He who controls the past controls the future. He who controls the present controls the past.
    • View Profile
    • Scripts
Re: Lenovo superfish scandel
« Reply #1 on: February 21, 2015, 11:36:20 pm »
Well I wouldn't say the Chinese because that's just ignorant, but never trust anyone/anything works ok for me.
Remember Lenovo is pretty much the most linux friendly brand for laptops.
Maybe they did this to make people switch to linux? lol.
Nah probably just wanted the extra $$$.

Simple solution:
Always wipe and reinstall OS on any hardware you buy. Takes care of the OEM crapware and any other nasties like this MITM cert that may be in your machine.
Jabber (OTR required): thed4rkcat@einfachjabber.de    Email (PGP required): thed4rkcat@yandex.com    PGP Key: here and here     Blog

<sofldan> not asking for anyone to hold my hand uber space shuttle door gunner guy.


Offline iTpHo3NiX

  • EZ's Pirate Captain
  • Administrator
  • Titan
  • *
  • Posts: 2920
  • Cookies: 328
    • View Profile
    • EvilZone
Re: Lenovo superfish scandel
« Reply #2 on: February 22, 2015, 03:07:37 am »
This affects a lot of end users as Lenovo has some of the best bangs for your buck as far as pricing and specs you get. Ive owned a couple of Lonovos. Luckily for me, the first step I take when purchasing a laptop is wipe all the OEM crap, partition my hard drive the way I like it to be for dual boot and I install an ultimate version of winblowz anyways
[09:27] (+lenoch) iTpHo3NiX can even manipulate me to suck dick
[09:27] (+lenoch) oh no that's voluntary
[09:27] (+lenoch) sorry

Offline Xeru

  • /dev/null
  • *
  • Posts: 5
  • Cookies: 3
  • Skype: unbans
    • View Profile
    • Xeru
Re: Lenovo superfish scandel
« Reply #3 on: February 22, 2015, 03:36:40 am »
Just hours before this news broke, I was reading up on how Lenovo was the "fastest growing PC company" or similar. What a shame, but it's funny that the article I previously mentioned was removed once the news broke. This was on a well-known news website.
Skype: Unbans
XMPP: xeru@podso.net
Blog: https://xeru.me

Offline Kulverstukas

  • Administrator
  • Zeus
  • *
  • Posts: 6627
  • Cookies: 542
  • Fascist dictator
    • View Profile
    • My blog
Re: Lenovo superfish scandel
« Reply #4 on: February 22, 2015, 11:29:38 am »
Simple solution:
Always wipe and reinstall OS on any hardware you buy. Takes care of the OEM crapware and any other nasties like this MITM cert that may be in your machine.
That's like... the first thing you do after buying a laptop with an OS - I tell that to everyone who gives a new laptop to me that is ALREADY slowing down because of all the crapware on it haha!
And I buy laptops without an OS, they are cheaper, because you don't buy the license...