Breaking News

ASUSTOR at Computex 2026 Exceed the Infinite with New ASRock X870E Taichi White Motherboard Fanatec unveils new products and performance upgrades at Spring Showcase LG Electronics Introduces First UltraGear evo Hyper Mini LED 5K Gaming Monitor CORSAIR Launches ThermalProtect PCIe 5.1 600W 12V-2x6 Cable to Help Protect GPUs from Overheating

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Lenovo Installed Adware on Laptops: report

Lenovo Installed Adware on Laptops: report

PC components Feb 19,2015 0

Lenovo, a huge maker of laptops, bundles virus-like software on laptops for the consumer market, cybersecurity experts said on Thursday. Users reported as early as last June that a browser add-on called Superfish Superfish Visual Discovery installed by Lenovo on consumer laptops automatically displayed adverts.

Robert Graham, CEO of U.S.-based security research firm Errata Security, said Superfish had been designed to intercept all encrypted connections in a poor way that it leaves the system open to hackers or NSA-style spies.

According to Marc Rogers (Errata Security), the software installs a transparent-proxy (MitM) service on the computer intercepting browser connections. However, such interception still cannot decrypt SSL. Therefore, SuperFish installs it's own root CA certificate in Windows system. It then generates certificates on the fly for each attempted SSL connection. Thus, when you have a Lenovo computer, it appears as SuperFish is the root CA of all the websites you visit. This allows SuperFish to intercept an encrypted SSL connection, decrypt it, then re-encrypt it again.

Only the traffic from the browser to the SuperFish internal proxy uses the website's certificate. The traffic on the Internet still uses the normal website's certificate, so we can't tell if a machine is infected by SuperFish by looking at this traffic. However, SuperFish makes queries to additional webpages to download it's JavaScript, which may be detectable.

SuperFish's advertising works by injecting JavaScript code into web-pages.

It's the same root CA private-key for every computer. This means that hackers at your local cafe WiFi hotspot, or the NSA eavesdropping on the Internet, can use that private-key to likewise intercept all SSL connections from SuperFish users.

Lenovo claims it's providing a useful service, helping users do price comparisons. However, they have stopped including the software on new systems.

Lenovo commanded one-fifth of the global PC market in the third quarter of 2014, according to data research firm IDC.

Tags: Lenovo
Previous Post
Shuttle Releases Broadwell-based Fanless PC
Next Post
Sony Launches Memory Card For Premium Sound

Related Posts

  • Lenovo Unveils Adaptive AI PCs, Modular Concepts, and Lenovo Qira Rollout at MWC 2026

  • Lenovo at CES 2026

  • All New Lenovo ThinkStation PGX

  • Lenovo at CES 2025

  • Leica completes trinity series for the SL-System

  • Lenovo AI-Driven Devices

  • Micron Delivers Crucial LPCAMM2 with LPDDR5X Memory for the New AI-Ready Lenovo ThinkPad P1 Gen 7 Workstation

  • Lenovo at CES 2024

Latest News

ASUSTOR at Computex 2026
Enterprise & IT

ASUSTOR at Computex 2026

Exceed the Infinite with New ASRock X870E Taichi White Motherboard
PC components

Exceed the Infinite with New ASRock X870E Taichi White Motherboard

Fanatec unveils new products and performance upgrades at Spring Showcase
Gaming

Fanatec unveils new products and performance upgrades at Spring Showcase

LG Electronics Introduces First UltraGear evo Hyper Mini LED 5K Gaming Monitor
Gaming

LG Electronics Introduces First UltraGear evo Hyper Mini LED 5K Gaming Monitor

CORSAIR Launches ThermalProtect PCIe 5.1 600W 12V-2x6 Cable to Help Protect GPUs from Overheating
Enterprise & IT

CORSAIR Launches ThermalProtect PCIe 5.1 600W 12V-2x6 Cable to Help Protect GPUs from Overheating

Popular Reviews

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

be quiet! Pure Loop 3 280mm

be quiet! Pure Loop 3 280mm

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

Soft2bet and the unseen hardware that makes instant play possible

Soft2bet and the unseen hardware that makes instant play possible

Crucial T710 2TB NVME SSD

Crucial T710 2TB NVME SSD

JSAUX 65Wh Rog Ally Battery

JSAUX 65Wh Rog Ally Battery

Introducing PriceHub

Introducing PriceHub

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed