Breaking News

TerraMaster Prime Day 2026 Sale Offers Up to 25% Off XPG Launches INFINITY Fans and MAESTRO Air Coolers Noctua introduces NL-LC1 all-in-one liquid coolers SAMA S50 Rethinks Compact ATX Cases Viltrox Launches AF 28mm F4.5 Chip L-mount Lens

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Lenovo Installed Adware on Laptops: report

Lenovo Installed Adware on Laptops: report

PC components Feb 19,2015 0

Lenovo, a huge maker of laptops, bundles virus-like software on laptops for the consumer market, cybersecurity experts said on Thursday. Users reported as early as last June that a browser add-on called Superfish Superfish Visual Discovery installed by Lenovo on consumer laptops automatically displayed adverts.

Robert Graham, CEO of U.S.-based security research firm Errata Security, said Superfish had been designed to intercept all encrypted connections in a poor way that it leaves the system open to hackers or NSA-style spies.

According to Marc Rogers (Errata Security), the software installs a transparent-proxy (MitM) service on the computer intercepting browser connections. However, such interception still cannot decrypt SSL. Therefore, SuperFish installs it's own root CA certificate in Windows system. It then generates certificates on the fly for each attempted SSL connection. Thus, when you have a Lenovo computer, it appears as SuperFish is the root CA of all the websites you visit. This allows SuperFish to intercept an encrypted SSL connection, decrypt it, then re-encrypt it again.

Only the traffic from the browser to the SuperFish internal proxy uses the website's certificate. The traffic on the Internet still uses the normal website's certificate, so we can't tell if a machine is infected by SuperFish by looking at this traffic. However, SuperFish makes queries to additional webpages to download it's JavaScript, which may be detectable.

SuperFish's advertising works by injecting JavaScript code into web-pages.

It's the same root CA private-key for every computer. This means that hackers at your local cafe WiFi hotspot, or the NSA eavesdropping on the Internet, can use that private-key to likewise intercept all SSL connections from SuperFish users.

Lenovo claims it's providing a useful service, helping users do price comparisons. However, they have stopped including the software on new systems.

Lenovo commanded one-fifth of the global PC market in the third quarter of 2014, according to data research firm IDC.

Tags: Lenovo
Previous Post
Shuttle Releases Broadwell-based Fanless PC
Next Post
Sony Launches Memory Card For Premium Sound

Related Posts

  • Lenovo Unveils Adaptive AI PCs, Modular Concepts, and Lenovo Qira Rollout at MWC 2026

  • Lenovo at CES 2026

  • All New Lenovo ThinkStation PGX

  • Lenovo at CES 2025

  • Leica completes trinity series for the SL-System

  • Lenovo AI-Driven Devices

  • Micron Delivers Crucial LPCAMM2 with LPDDR5X Memory for the New AI-Ready Lenovo ThinkPad P1 Gen 7 Workstation

  • Lenovo at CES 2024

Latest News

TerraMaster Prime Day 2026 Sale Offers Up to 25% Off
Enterprise & IT

TerraMaster Prime Day 2026 Sale Offers Up to 25% Off

XPG Launches INFINITY Fans and MAESTRO Air Coolers
Cooling Systems

XPG Launches INFINITY Fans and MAESTRO Air Coolers

Noctua introduces NL-LC1 all-in-one liquid coolers
Cooling Systems

Noctua introduces NL-LC1 all-in-one liquid coolers

SAMA S50 Rethinks Compact ATX Cases
Cooling Systems

SAMA S50 Rethinks Compact ATX Cases

Viltrox Launches AF 28mm F4.5 Chip L-mount Lens
Cameras

Viltrox Launches AF 28mm F4.5 Chip L-mount Lens

Popular Reviews

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

Endorfy Thock V2 Wireless Keyboard

Endorfy Thock V2 Wireless Keyboard

be quiet! Pure Loop 3 280mm

be quiet! Pure Loop 3 280mm

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

Soft2bet and the unseen hardware that makes instant play possible

Soft2bet and the unseen hardware that makes instant play possible

Crucial T710 2TB NVME SSD

Crucial T710 2TB NVME SSD

be quiet! Pure power 13M 750W

be quiet! Pure power 13M 750W

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed