Results 1 to 2 of 2
  1. #1
    Thailand Expat

    Join Date
    Feb 2009
    Last Online
    04-11-2019 @ 05:15 AM
    Posts
    3,857

    Lenovo admits to Superfish screw-up

    Lenovo admits to Superfish screw-up, will release clean-up tool



    Lenovo has admitted it “messed up badly” by pre-loading software on some consumer laptops that exposed users to possible attack, and said it will soon release a tool to remove it.


    “I have a bunch of very embarrassed engineers on my staff right now,” Lenovo CTO Peter Hortensius said in an interview Thursday. “They missed this.”
    Users have been complaining since September about the third-party program, called Superfish, which injects product recommendations into search results. But it only emerged Wednesday that the program also opens a serious security hole.


    The program interferes with SSL-encrypted Web traffic by installing its own root certificate in the trusted certificate store used by browsers. It then uses it to generate SSL certificates for HTTPS-enabled websites when they are visited by users. This allows it to act as a man-in-the-middle proxy between users and those secure websites.




    http://www.pcworld.com/article/2886912/lenovo-admits-to-superfish-screwup-






    They're 'embarrased' because the adware/malware they preload has a security hole??


    Wtf.

  2. #2

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •