Unconfigured Ad Widget

Collapse

Lenovo Superfish

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • penguin0123
    Veteran Member
    • Dec 2011
    • 3089

    Lenovo Superfish

    Lenovo has been preloading new consumer PCs with Superfish adware that injects ads and hijacks the secure HTTPS encryption of every site you visit. Eradicating the threat isn't easy, but here's how, complete with a new automated tool.


    The company has been preloading Superfish, a "visual search" tool that includes adware that fakes the encryption certificates for every HTTPS-protected site you visit, on its PCs since at least the middle of 2014. Essentially, the software conducts a man-in-the-middle attack to fill the websites you visit with ads, and leaves you vulnerable to hackers in its wake.
  • #2
    C.G.
    Calguns Addict
    • Oct 2005
    • 8250

    I never installed Superfish but after this thing came out I found the Superfish Security Certificate installed, which I promptly deleted.
    sigpic

    Comment

    • #3
      Zorba
      Banned
      • May 2014
      • 767

      Its been my experience that Lenovos come pre-loaded with more crapware than just about anybody. Certainly to the point of where I don't like to deal with them. In my opinion, if you have the knowledge, the best thing you can possibly do with a new PC from just about any/everybody is to do a re-install of the operating system. Doing so usually takes little more time than removing the crapware, and the results are often better!

      Comment

      • #4
        Mute
        Calguns Addict
        • Oct 2005
        • 8595

        Originally posted by C.G.
        I never installed Superfish but after this thing came out I found the Superfish Security Certificate installed, which I promptly deleted.
        Did you manually delete the security certificate? Uninstalling the adware, while good, doesn't get rid of the certificate vulnerability. You need to make sure the certificate has been undone.
        NRA Benefactor Life Member
        NRA Certified Pistol, Rifle, Personal Protection In The Home, Personal Protection Outside The Home Instructor, CA DOJ Certified CCW Instructor, RSO


        American Marksman Training Group
        Visit our American Marksman Facebook Page

        Comment

        • #5
          C.G.
          Calguns Addict
          • Oct 2005
          • 8250

          Originally posted by Mute
          Did you manually delete the security certificate? Uninstalling the adware, while good, doesn't get rid of the certificate vulnerability. You need to make sure the certificate has been undone.
          Actually I never installed the software, but the certificate was there anyway in spite of the fact. And yes, I uninstalled the certificate manually.
          sigpic

          Comment

          • #6
            Mute
            Calguns Addict
            • Oct 2005
            • 8595

            Originally posted by C.G.
            Actually I never installed the software, but the certificate was there anyway in spite of the fact. And yes, I uninstalled the certificate manually.
            It's because Lenovo decided to include that crap bloatware in their OS install from the factory. If anyone gets harmed by this, Lenovo could be in for a world of hurt.
            NRA Benefactor Life Member
            NRA Certified Pistol, Rifle, Personal Protection In The Home, Personal Protection Outside The Home Instructor, CA DOJ Certified CCW Instructor, RSO


            American Marksman Training Group
            Visit our American Marksman Facebook Page

            Comment

            • #7
              Bryansix
              Calguns Addict
              • Feb 2011
              • 5311

              Lenovo is already being sued over this. I hope as a result of this that they release a clean install option on their computers. Only one manufacturer I know does this. That manufacturer is PowerSpec.
              My Guns:
              SP 2022 9mm - 2575 rounds
              Hi-Point Carbine 9mm | Bushnell TRS-25 Red Dot |Magpul BUIS 45 degree offset - 140 rounds
              "Reloading is kind of like crocheting for the gun enthusiast with the one exception that while you can have too many drink coasters and ski hats, you cannot have too much ammo." ~Bryansix

              Comment

              • #8
                KillZone45
                Veteran Member
                • Sep 2009
                • 2570

                Originally posted by Bryansix
                Lenovo is already being sued over this. I hope as a result of this that they release a clean install option on their computers. Only one manufacturer I know does this. That manufacturer is PowerSpec.
                Class action lawsuit, I had to deal with Superfish and it was extremely annoying! Hopefully I can get something out of this like credit or what ever. It was def BS for them to install this. Bought a new Lenovo and literally the next day I found out about Superfish. Was easy peazy to remove though.
                Nikita Khrushchev said"We can't expect the American People to jump from Capitalism to Communism, but we can assist their elected leaders in giving them small doses of Socialism, until they awaken one day to find that they have Communism. "

                Comment

                • #9
                  PanchoVilla
                  Senior Member
                  • Aug 2009
                  • 504

                  we got a yoga 2 pro at Christmas. Had a minor freakout when I realized our model included. Luckily not superfish and no cert on our machine. Since we bought at very end of dec I guess we got lucky and no install. I will definitely go through the machine now hearing that Lenovo is tops when it comes to crapware installs I am sure there is some other stuff I can remove too.

                  Comment

                  • #10
                    OlderThanDirt
                    FUBAR
                    CGN Contributor - Lifetime
                    • Jun 2009
                    • 6002

                    Am I the only one that is highly suspicious of companies like Lenovo that are Chinese owned? Besides Superfish, how would someone ever know if there isn't something equally as invasive written into the bios or even some of the hardware. Maybe I'm just being paranoid and nobody would ever use companies Seagate, Micron or Western Digital to spy on people.

                    Flooding a country with cheap hardware infected with spyware and viruses that can be activated at will would be a great way to bring it's communications infrastructure to a grinding halt.
                    We know they are lying, they know they are lying, they know we know they are lying, we know they know we know they are lying, but they are still lying. ~ Solzhenitsyn
                    Thermidorian Reaction . . Prepare for it.

                    Comment

                    • #11
                      NYT
                      CGN/CGSSA Contributor
                      CGN Contributor
                      • Apr 2011
                      • 3811

                      lenovo is actually one of the few companies that provide an "install path" for IT departments that build their own images. they release these generic images on their systems for the general public that does what the general public does, shops online. superfish was designed to do just that. the problem is that the software wasnt fully vetted by security personnel, thus lenovo is in trouble and superfish is most likely going to be out of business soon.

                      everyone should be building their own images to run as clean an install of windows as possible. i buy lenovo x1 carbon ultrabooks for my staff because theyre the best all around laptop you can buy for the money.



                      some good info:

                      Comment

                      Working...
                      UA-8071174-1