Lenovo Owners Beware

Snipeye

EGO Is My Life!
=(e)=
Joined
May 6, 2009
Messages
4,867
How could Lenovo miss its Superfish security hole?
blogger-avatarby Richard Lawler | @rjcc | February 20th 2015 at 6:45 pm

Until mid-day yesterday Lenovo thought the biggest problem with Superfish VisualDiscovery was the annoying ads it caused to pop up on customers' laptops. SuperFish was supposed to analyze images on the web and "help" consumers find similar products, but the information security world was learning that it (apparently unintentionally) does quite a bit more. Facebook engineer Mike Shaver tweeted Wednesday night about how the preloaded adware performs a man-in-the-middle (MITM) attack on supposedly secure connections, and by Thursday morning security researcher Rob Graham showed how it could be used to spy on the encrypted communications of anyone running the software. At that point, Levono CTO Peter Hortensius still referred to resulting security problems as "thoretical" but moves today from Microsoft and the US government -- and his comments to us -- show that they've realized the threat is very real.

Update: Lenovo has just released a Superfish removal tool. In an accompanying statement (included after the break), the company says it's also working with McAfee so that virus scanners will remove the software and its certificate.

Now, Lenovo admits to the gravity of the problem (even if the company behind Superfish does not, as shown by a spokesperson's comments to Ars Technica) and is working with others in the industry to fix it. Still, the question remains -- how did a security hole this problematic get there in the first place? As Hortensius told me, that's the question he and his team will be trying to answer over the next week or so.

How to make Superfish go away

The first priority is making sure that Superfish disappears and the security hole is closed, and there's several ways to make sure your PC is secured. Browser test pages (Filippo.io, LastPass) can tell you if you're affected and give tips on removal. Lenovo has its own list of uninstallation instructions, and as of today Microsoft's Windows Defender scanner has been updated to remove Superfish and its security certificate. You can expect for other scanners to get a similar update soon, and of course Lenovo is working on an uninstall program of its own that could be available later today.

Why is Superfish such a big problem?

Superfish's security problems are worsened by practices researchers have uncovered over the last day or so: not only is its security certificate easily extracted, as Rob Graham discovered, it uses the same one on every computer. It appears that Superfish (and others) used technology from a company called Komodia to pull off its hamfisted intervention, and all of them are equally vulnerable. Even worse, beyond the initially discovered MITM vulnerability and weak encryption, the Komodia package can be easily tricked into accepting any certificate as valid. According to CloudFlare security team member Filippo Valsorda, that means it's easy to intercept encrypted traffic from anyone with Komodia-powered software on their system.

What is Lenovo doing about it

While we wait to find out the next way this will get worse, Lenovo says it is taking steps to turn things around. Of course, as security researcher Kenn White asked, after the company ignored respected security researchers "activating the Batsignal", restoring its public trust will be tricky. The software appeared on computers beginning in September, and posters on Lenovo support forums were asking questions that should've raised alarms for months.

According to Hortensius, Lenovo does security checks for software that it preloads, but apparently Superfish bypassed those even with this glaring security hole. He says "If we knew then what we know now, we'd never have shipped this", and that security practices, even the ones the company will institute going forward can never be 100 percent. He says that information with real substance is coming, that will detail how Lenovo plans to avoid getting caught out like this again, which will be key. Patching the software is relatively simple -- filling in this hole in the company's reputation may not be so easy.

As we've said previously, Lenovo is exploring every action we can to help our users address the concerns around Superfish. In addition to the actions that we have already taken we are:

1) In addition to the manual removal instructions currently available online, we have released an automated tool to help users remove the software and certificate. That tool is here: http://support.lenovo.com/us/en/product_security/superfish_uninstall

2) We are working with McAfee and Microsoft to have the Superfish software and certificate quarantined or removed using their industry-leading tools and technologies. This action has already started and will automatically fix the vulnerability even for users who are not currently aware of the problem.
We ordered Superfish pre-loads to stop and had server connections shut down in January based on user complaints about the experience. However, we did not know about this potential security vulnerability until yesterday. We recognize that this was our miss, and we will do better in the future. Now we are focused on fixing it.

Since that time we have moved as swiftly and decisively as we can based on what we now know. While this issue in no way impacts our ThinkPads; any tablets, desktops or smartphones; or any enterprise server or storage device, we recognize that all Lenovo customers need to be informed. We apologize for causing these concerns among our users for any reason ? and we are learning from experience and improve what we do and how we do it. We will continue to take steps to make removal of the software and underlying vulnerable certificates in question easy for customers so they can continue to use our products with the confidence that they expect and deserve.

http://www.engadget.com/2015/02/20/lenovo-superfish-cto/
 
Superfish doubles down, says HTTPS-busting adware poses no security risk

Superfish doubles down, says HTTPS-busting adware poses no security risk
Denial comes despite near-unanimous agreement that it left Lenovo users wide open.


by Dan Goodin - Feb 20, 2015 4:20pm EST

Following security professionals' near-unanimous condemnation of adware that hijacked encrypted Web connections on Lenovo computers, the CEO of the company that developed the finished product is doubling down on his insistence that it poses no threat to end users.

Superfish may make it trivial for attackers to spoof any HTTPS website.
The statement, e-mailed to Ars by a Superfish spokeswoman and attributed to company CEO Adi Pinhas, is notable for making no reference to secure sockets layer, transport layer security, HTTPS, or any other form of encryption. Those technologies are at the core of security researchers' criticisms. They say the self-signed certificates, registered to Superfish and installed in the root level of every PC's SSL/TLS folder, makes it easy for malicious hackers and even script kiddies to build websites that trick affected browsers into behaving as if they're connected to servers for Bank of America, Google, or any other HTTPS-protected website on the Internet. In fact, there's near-universal agreement about this. Earlier today, the US CERT joined the growing chorus of critics with an advisory headlined "Lenovo Computers Vulnerable to HTTPS Spoofing."
Update: It turns out the vulnerability is easier to exploit than previously known. As this post was being prepared, a security researcher published new findings showing that a malicious hacker doesn't need the easily-extracted Superfish private key to perform a man-in-the-middle attack on PCs that have the Komodia proxy installed. That's because the proxy will re-sign invalid certs and make them appear valid to the browser.

Despite all of this, Pinhas's statement doesn't address the criticism. Instead, it attacks an argument that no one has made—that Superfish somehow shares personal information without users' permission. Here is the statement in full:

Superfish Statement from CEO

There has been significant misinformation circulating about Superfish software that was pre-installed on certain Lenovo laptops. The software shipped on a limited number of computers in 2014 in an effort to enhance the online shopping experience for Lenovo customers. Superfish's software utilizes visual search technology to help users achieve more relevant search results based on images of products they have browsed.

Despite the false and misleading statements made by some media commentators and bloggers, the Superfish software does not present a security risk. In no way does Superfish store personal data or share such data with anyone. Unfortunately, in this situation a vulnerability was introduced unintentionally by a 3rd party. Both Lenovo and Superfish did extensive testing of the solution but this issue wasn't identified before some laptops shipped. Fortunately, our partnership with Lenovo was limited in scale. We were able to address the issue quickly. The software was disabled on the server side (i.e., Superfish's search engine) in January 2015.

Superfish takes great pride in the quality of its software, the transparency of its business practices, and its strong relationship with the Superfish user community. Superfish's visual search technology enables millions of people to explore and learn about the world in an engaging and highly intuitive manner. A positive user experience has been the cornerstone of Superfish's success.


The Superfish spokeswoman didn't respond to an e-mail from Ars requesting an interview with the CEO.

On Thursday, Superfish officials said they stood by a statement issued by Lenovo that said, "We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns." Within hours, Lenovo yanked that sentence from the statement and issued a mea culpa from the company's CTO.

It's hard to fathom how a technology company versed in the inner workings of HTTPS can continue to say that the implementation of Superfish that was installed on an undisclosed number of Lenovo laptops posed no security threat. The certificate that makes the security vulnerability possible clearly carries the Superfish name, was installed as part of the Superfish software, and was produced in collaboration with Komodia, a company Superfish has acknowledged it hired to work on the Lenovo implementation. It's possible the oblique reference to a vulnerability from a third party gave Superfish officials the wiggle room they thought would insulate them. But all it's really doing is making it clear that Pinhas has trouble owning up to the decisions made by his own company.

That's too bad. The CEO had a chance to regain the trust of some people by providing a detailed autopsy that explained how software with his company's name on it put so many Lenovo users at risk. This missed opportunity may make it impossible for him to repair the damage now.

http://arstechnica.com/security/201...-https-busting-adware-poses-no-security-risk/
 
And this is why I always just reinstall Windows when I get a computer from any sort of brand like this
 
I remember finding that SuperFish installed on my PC and I didn't know what it was, beyond the Internet calling it malware. I removed it ASAP (with other programs trying to speed my laptop up). Go figure that it worked out for the better with this news.

BTW, Hi iSimon! Where you've been? Haven't seen you post on here for some time.
 
Lenovo should be releasing a removal tool to fix this.
EDIT: I see you already added this :)

We sell them at the store I work at. We're offering free removal to anyone who purchased the laptop from us.
 
I remember finding that SuperFish installed on my PC and I didn't know what it was, beyond the Internet calling it malware. I removed it ASAP (with other programs trying to speed my laptop up). Go figure that it worked out for the better with this news.

BTW, Hi iSimon! Where you've been? Haven't seen you post on here for some time.

I lurk around every so often ;) I'm well!
 

Latest posts

Back
Top