Skip to main content

Updated: Purchased a Lenovo PC recently? It might have adware – and a critical HTTPS vulnerability

Updated: 2/20/2015 2:53 PM

Lenovo has produced a list of systems that “may have” Superfish installed. They include.

Recommended Videos

G Series: G410, G510, G710, G40-70, G50-70, G40-30, G50-30, G40-45, G50-45
U Series: U330P, U430P, U330Touch, U430Touch, U530Touch
Y Series: Y430P, Y40-70, Y50-70
Z Series: Z40-75, Z50-75, Z40-70, Z50-70
S Series: S310, S410, S40-70, S415, S415Touch, S20-30, S20-30Touch
Flex Series: Flex2 14D, Flex2 15D, Flex2 14, Flex2 15, Flex2 14(BTM), Flex2 15(BTM), Flex 10
MIIX Series: MIIX2-8, MIIX2-10, MIIX2-11
YOGA Series: YOGA2Pro-13, YOGA2-13, YOGA2-11BTM, YOGA2-11HSW
E Series: E10-30

Please enable Javascript to view this content

It appears ThinkPad systems were spared, which is good news for enterprise users concerned about security.

Have you purchased a Lenovo computer lately? Then you may be vulnerable to a “man-in-the-middle” attack that can steal information from websites that appear secured by HTTPS. The attack is possible because of adware installed on the company’s machines at the factory.

The adware, known as Superfish, uses ad injection to place advertisements into websites that are not normally there, or interrupt loading of a site and show an additional ad. Lenovo says this function is now disabled on the server side.

Related: Adware app found in Google Play store

More troubling still, the adware breaks HTTPS connections to achieve its goals. It does this through a self-signed security certificate that can intercept those normally used by websites. The site still appears secure, as normal, but when its certificate is examined it’s shown to belong to Superfish, rather than the site visited.

Security researchers have also discovered the Superfish-signed certification appears to be the same on every Lenovo computer, and is protected by a rather simple security password. Rob Graham, CEO of Errata Security, claims he cracked the password, and found it to be “komodia.”

See the problem? If not, here’s the basic version: malicious hackers can now potentially hijack the Superfish certificate’s credentials, and because the certificate replaces those normally used by sites that secured through HTTPS, doing so effectively lets an attacker masquerade as any HTTPS secured site on a Lenovo PC. Google, your bank, your credit card company; connections to all of these, and more, are vulnerable to man-in-the-middle attacks.

Related: Forged security certificate targets Gmail users

Lenovo, in its official response, states “We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns.” Unfortunately, though, the company has not made an effort to specifically refute the vulnerability demonstrated by security researchers. No new Lenovo PCs are shipping with Superfish as of January, but that does not guarantee currently available models lack the issue, as systems sometimes linger in inventory for months.

The statement also says Superfish does not track user behavior or record user information. No security researcher has accused Lenovo of that, but it’s easy to understand why some users might believe that, too, was a possibility.

Obviously, this is a significant issue given Lenovo’s position as one of the world’s largest PC manufacturers. The company also has significant enterprise presence with its ThinkPad line, and those users are often particularly concerned with security. No one knows exactly which systems had Superfish installed besides Lenovo, but there could be millions now in the wild with this critical vulnerability.

The company’s support forums provide a way to uninstall Superfish, but users who’ve tried it so far claim it does not remove the false certification. Let’s hope Lenovo finds a way to help users patch their systems.

Matthew S. Smith
Matthew S. Smith is the former Lead Editor, Reviews at Digital Trends. He previously guided the Products Team, which dives…
Google’s new satellite network can help spot wildfires
penny machine learning income predictor 30619164  space satellite orbiting the earth

The first FireSat satellite has launched and made a connection with Earth. The FireSat system is a collaborative effort between Google Research, Muon Space, Earth Fire Alliance, Moore Foundation, and numerous other agencies, and it has a single, deceptively simple purpose: to detect wildfires before they become too hard to contain and control.

Wildfires have been a constant problem for agencies. Early detection is vital, but fires can often start in subtle ways; by the time anyone notices the growing blaze, it's too late to stop. Just take the wildfires in Los Angeles earlier this year as an example. Apps have been created to crowdsource fire detection, and the traditional method of watching for wildfires is through satellite imagery.

Read more
Buy this Samsung 49-inch OLED monitor deal and get a free 4TB SSD
The Samsung Odyssey OLED G9 monitor with 990 Pro SSD on a white background.

If you're thinking about making some upgrades to your PC gaming setup, you can take advantage of monitor deals and SSD deals with just one purchase through this interesting offer from Samsung. A bundle that combines the 49-inch Samsung Odyssey OLED G9 gaming monitor and the 4TB Samsung 990 Pro SSD is on sale, dropping the total price from $2,300 to only $1,634. That's $666 in savings that you won't find anywhere else, but you need to hurry if you don't want to miss out because there's no telling when the discount ends.

Why you should buy the 49-inch Samsung Odyssey OLED G9 gaming monitor and 4TB Samsung 990 Pro SSD
The Samsung Odyssey OLED G9 is featured in our roundup of the best gaming monitors as the best 32:9 gaming monitor, as it provides an unmatched immersive experience with OLED technology and a dual QHD resolution for vibrant colors and lifelike images, a 240Hz refresh rate for smooth animations on the screen, and a 0.03ms response time that could give you the edge over the competition. The gaming monitor also supports Nvidia's G-Sync and AMD's FreeSync Premium Pro, which will eliminate screen tearing and stuttering.

Read more
China joins the global push for AI content regulation
AI chatbots.

Many international entities are pushing for better regulation of AI-generated content on the internet– and China’s government is the latest to reign in the use of the quickly developing technology.

According to Bloomberg, several government ministries have joined with the Chinese internet watchdog Cyberspace Administration of China (CAC) to announce a new mandate that will require internet users to identify any AI-generated content as such in a description or metadata encoding.

Read more