Login    Forum    Search    FAQ

Board index » Upgrading and Repairing Forum » Laptop Hardware




Post new topic Reply to topic  [ 4 posts ] 
Author Message
 Post subject: Got Superfish?
 Post Posted: Thu Feb 19, 2015 8:14 pm 
Offline

Joined: Sun Jul 20, 2008 10:50 am
Posts: 508
Location: Phoenix, AZ, USA
True for laptops and desktops.

Bought a Lenovo recently? Congratulations! They installed some malware for free called Superfish:

Lenovo PCs ship with man-in-the-middle adware that breaks HTTPS connections

ARS Technica
Feb. 19, 2015

http://arstechnica.com/security/2015/02 ... nnections/

Lenovo is selling computers that come preinstalled with adware that hijacks encrypted Web sessions and may make users vulnerable to HTTPS man-in-the-middle attacks that are trivial for attackers to carry out, security researchers said.

The critical threat is present on Lenovo PCs that have adware from a company called Superfish installed. As unsavory as many people find software that injects ads into Web pages, there's something much more nefarious about the Superfish package. It installs a self-signed root HTTPS certificate that can intercept encrypted traffic for every website a user visits. When a user visits an HTTPS site, the site certificate is signed and controlled by Superfish and falsely represents itself as the official website certificate.... [continue reading at above link]



How to remove the Superfish malware: What Lenovo doesn’t tell you

ARS Technica
Feb. 19, 2015

http://arstechnica.com/security/2015/02 ... -tell-you/

Uninstalling the software doesn't undo the damage it does to your system.


Top 
 Profile  
Reply with quote  
 Post subject: Re: Got Superfish?
 Post Posted: Thu Feb 19, 2015 8:45 pm 
Offline
Site Admin

Joined: Sun Feb 04, 2007 11:44 am
Posts: 5766
That is indeed some unfortunate news. However, the good news is that this software was *NEVER* installed on any ThinkPad systems, and it was only installed on consumer grade systems shipped between October and December 2014. While that does not excuse this atrocity, it is another reason I only recommend Lenovo *ThinkPads*. Scott.


Top 
 Profile  
Reply with quote  
 Post subject: Re: Got Superfish?
 Post Posted: Sat Feb 21, 2015 10:38 pm 
Offline

Joined: Thu Jan 15, 2009 1:27 pm
Posts: 1105
Location: Stowmarket, Suffolk England
Removal instructions here in PDF format

http://news.lenovo.com/images/20034/rem ... ctions.pdf


Includes how to remove the certificate.


Top 
 Profile  
Reply with quote  
 Post subject: Re: Got Superfish?
 Post Posted: Sun Feb 22, 2015 1:47 am 
Offline
Site Admin

Joined: Sun Feb 04, 2007 11:44 am
Posts: 5766
You no longer need to do it manually. Here is a tool Lenovo just released to automatically and completely remove the Superfish software and certificates: http://support.lenovo.com/us/en/product ... _uninstall

Here is an official Lenovo statement on the subject: http://news.lenovo.com/article_display. ... w_id=1431&

Scott.


Top 
 Profile  
Reply with quote  
Display posts from previous:  Sort by  
 
Post new topic Reply to topic  [ 4 posts ] 

Board index » Upgrading and Repairing Forum » Laptop Hardware


Who is online

Users browsing this forum: Bing [Bot] and 2 guests

 
 

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
cron