Breaking News

ASUS Announces Intel Core Ultra 200S Plus Series Support on W880, Z890, Q870, B860 and H810 Motherboards G.SKILL DDR5 Memory Kits Confirmed as Intel XMP 3.0 'Ready' for Intel Core Ultra 200S Plus Series Processors ASUS Unveils Complete Portfolio Support for Intel Core 200S Series Samsung Brings AirDrop Support to Quick Share with Galaxy S26 Series TerraMaster Spring Sale 2026 Upgraded Up To 30%

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Lenovo Settles FTC Charges it Harmed Consumers With Preinstalled Adware on its Laptops

Lenovo Settles FTC Charges it Harmed Consumers With Preinstalled Adware on its Laptops

PC components Sep 5,2017 0

Lenovo Inc. has agreed to settle charges by the Federal Trade Commission and 32 State Attorneys General that the company harmed consumers by pre-loading software on some laptops that compromised security protections in order to deliver ads to consumers.

In its complaint, the FTC charged that beginning in August 2014 Lenovo began selling consumer laptops in the United States that came with a preinstalled "man-in-the-middle" software program called VisualDiscovery that interfered with how a user's browser interacted with websites and created serious security vulnerabilities.

"Lenovo compromised consumers' privacy when it preloaded software that could access consumers' sensitive information without adequate notice or consent to its use," said Acting FTC Chairman Maureen K. Ohlhausen. "This conduct is even more serious because the software compromised online security protections that consumers rely on."

VisualDiscovery software, developed by a company called Superfish, Inc., was installed on hundreds of thousands of Lenovo laptops. It delivered pop-up ads from the company's retail partners whenever a user's cursor hovered over a similar looking product on a website.

To deliver its ads, VisualDiscovery acted as a "man-in-the-middle" between consumers' browsers and the websites they visited, even those websites that were encrypted. Without the consumer's knowledge or consent, this technique allowed VisualDiscovery to access all of a consumer's sensitive personal information transmitted over the Internet, including login credentials, Social Security numbers, medical information, and financial and payment information. While VisualDiscovery collected and transmitted to Superfish's servers more limited information, such as the websites the user browsed and the consumer's IP address, Superfish had the ability to collect more information.

The complaint also alleges that VisualDiscovery used an insecure method to replace digital certificates for those websites with its own VisualDiscovery-signed certificates. Digital certificates are used to signal to a user's browser that the encrypted websites visited by a consumer are authentic and not imposters. VisualDiscovery, however, did not adequately verify that the websites' digital certificates were valid before replacing them, and used the same, easy-to-crack password on all affected laptops rather than using unique passwords for each laptop.

Because of these security vulnerabilities, consumers' browsers could not warn users when they visited potentially spoofed or malicious websites with invalid digital certificates. The vulnerabilities also enabled potential attackers to intercept consumers' electronic communications with any website, including financial institutions and medical providers, by simply cracking the pre-installed password. The complaint alleges that Lenovo did not discover these security vulnerabilities because it failed to assess and address security risks created by third-party software it preloaded on its laptops.

As part of the settlement with the FTC, Lenovo is prohibited from misrepresenting any features of software preloaded on laptops that will inject advertising into consumers' Internet browsing sessions or transmit sensitive consumer information to third parties. The company must also get consumers' affirmative consent before pre-installing this type of software. In addition, the company is required for 20 years to implement a comprehensive software security program for most consumer software preloaded on its laptops. The security program will also be subject to third-party audits.

Tags: Lenovo
Previous Post
Nissan Leaf Got Upgraded to Compete With Tesla's Models
Next Post
Western Digital Could Quit Bid for Toshiba Chip Unit, for Better JV Terms

Related Posts

  • Lenovo Unveils Adaptive AI PCs, Modular Concepts, and Lenovo Qira Rollout at MWC 2026

  • Lenovo at CES 2026

  • All New Lenovo ThinkStation PGX

  • Lenovo at CES 2025

  • Leica completes trinity series for the SL-System

  • Lenovo AI-Driven Devices

  • Micron Delivers Crucial LPCAMM2 with LPDDR5X Memory for the New AI-Ready Lenovo ThinkPad P1 Gen 7 Workstation

  • Lenovo at CES 2024

Latest News

ASUS Announces Intel Core Ultra 200S Plus Series Support on W880, Z890, Q870, B860 and H810 Motherboards
Enterprise & IT

ASUS Announces Intel Core Ultra 200S Plus Series Support on W880, Z890, Q870, B860 and H810 Motherboards

G.SKILL DDR5 Memory Kits Confirmed as Intel XMP 3.0 'Ready' for Intel Core Ultra 200S Plus Series Processors
PC components

G.SKILL DDR5 Memory Kits Confirmed as Intel XMP 3.0 'Ready' for Intel Core Ultra 200S Plus Series Processors

ASUS Unveils Complete Portfolio Support for Intel Core 200S Series
Enterprise & IT

ASUS Unveils Complete Portfolio Support for Intel Core 200S Series

Samsung Brings AirDrop Support to Quick Share with Galaxy S26 Series
Smartphones

Samsung Brings AirDrop Support to Quick Share with Galaxy S26 Series

TerraMaster Spring Sale 2026 Upgraded Up To 30%
Enterprise & IT

TerraMaster Spring Sale 2026 Upgraded Up To 30%

Popular Reviews

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

be quiet! Pure Loop 3 280mm

be quiet! Pure Loop 3 280mm

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

Arctic Liquid Freezer III 360 Pro Argb

Arctic Liquid Freezer III 360 Pro Argb

Soft2bet and the unseen hardware that makes instant play possible

Soft2bet and the unseen hardware that makes instant play possible

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed