Advertisement

We need your help now

Support from readers like you keeps The Journal open.

You are visiting us because we have something you value. Independent, unbiased news that tells the truth. Advertising revenue goes some way to support our mission, but this year it has not been enough.

If you've seen value in our reporting, please contribute what you can, so we can continue to produce accurate and meaningful journalism. For everyone who needs it.

AP Photo/Andy Wong

If you bought a Lenovo laptop recently, you may want to check it soon

It could have software called Superfish, and it contains some major security flaws (but you can remove it).

IF YOU’VE BOUGHT a Levono device in recent times, then it may have come with adware known as Visual Discovery by Superfish, and it’s a major problem.

Effectively, Superfish is a software add-on which serves to bring up extra ads while you’re browsing a site, even if it’s a secure HTTPS site.

However, the flaws in its security would allow any hacker to carry out man-in-the-middle attacks, which allows them to both intercept messages as well as alter them or include their own messages. This means that private and secure information like passwords, financial details and personal information could be intercepted.

Superfish wasn’t intended as malware. Lenovo has said it was designed to show targeted ads by analyzing images of products that a user might see on the web and then presenting “identical and similar product offers that may have lower prices.” Lenovo said the software doesn’t track users or collect any identifying information.

But some users initially complained the software shows unwanted “pop-up” ads. And this week, several independent experts reported that Superfish works by substituting its own security key for the encryption certificates that many websites use to protect users’ information. “This means that anyone affected by this adware cannot trust any secure connections they make,” researcher Marc Rogers wrote on his blog.

What’s worse, experts said, is that Superfish appears to re-use the same encryption certificate for every computer, which means a hacker who cracked the Superfish key could have broad access to a variety of online transactions.

The CEO of Errata Security, Robert Graham discovered that it allowed him to intercept encrypted communications of anyone using Superfish by being near them at a cafe WiFi hotspot.

In a statement, Lenovo said it stopped the preloads back in January models and listed the models Superfish would have appeared on.

We thought the product would enhance the shopping experience, as intended by Superfish. It did not meet our expectations or those of our customers. In reality, we had customer complaints about the software.  We acted swiftly and decisively once these concerns began to be raised. We apologize for causing any concern to any users for any reason – and we are always trying to learn from experience and improve what we do and how we do it.

How to remove it

If you do own a Lenovo computer and want to remove it, there are a few methods to use. The easiest way to check is to use a web service from password manager LastPass, which will tell you if your computer is safe or not.

If you do have it installed, then it details how exactly you can uninstall both the programme and the certificates it uses. Even if it comes up as safe, it’s worth delving into control panel just to be on the safe side.

Once that’s done, it’s recommended that you change your passwords to any online services that you use. You could use a password manager like LastPass to create more complex passwords or other services like 1Password or KeePass.

(Additional reporting by AP)

Read: Uber thinks it can deliver your takeaway in ten minutes >

Read: This is why Snapchat fully deserves a €16 billion valuation >

Readers like you are keeping these stories free for everyone...
A mix of advertising and supporting contributions helps keep paywalls away from valuable information like this article. Over 5,000 readers like you have already stepped up and support us with a monthly payment or a once-off donation.

Close
23 Comments
    Install the app to use these features.
    Mute Martin Byrne
    Favourite Martin Byrne
    Report
    Feb 20th 2015, 8:28 AM

    I’m never buying Lenovo again, nor is my company.

    48
    Install the app to use these features.
    Mute Niallers
    Favourite Niallers
    Report
    Feb 20th 2015, 8:35 AM

    I’l never buy a Lenova again.Total rubbish and poor quality compared to Dell. Dell laptops are way better build quality and last longer and don’t come loaded with malware like Lenova do. Lenova depends on this adware/malware to make the unit profitable.

    31
    Install the app to use these features.
    Mute Barry O'Brien
    Favourite Barry O'Brien
    Report
    Feb 20th 2015, 8:51 AM

    It’s a Chinese company. Shock, horror! It has malware preloaded!

    The IBM Thinkpads (and early Lenovo Thinkpads based on IBM’s) were fantastic. Now I wouldn’t touch one.

    37
    See 3 more replies ▾
    Install the app to use these features.
    Mute Fin Tastic
    Favourite Fin Tastic
    Report
    Feb 20th 2015, 12:18 PM

    Well done there Barry on your top casual racism. We all know the Chinese were the first to load bloatware/spyware on PCs/laptops.

    13
    Install the app to use these features.
    Mute Jed I. Knight
    Favourite Jed I. Knight
    Report
    Feb 20th 2015, 1:03 PM

    The Lenovo laptops themselves are as good or bad as most other companies out there, there are better and worse, but for them to knowingly and intentionally sell laptops with this software which can steal web traffic using a traffic using man-in-the-middle attack is criminal.
    The Superfish software was present on their laptops until late last month, so far there’s no indication how far back this went, it used fake, self-signed, root certificates, they only removed it when users began complaining about it on forums. Lenovo said;
    “we have temporarily removed Superfish from our consumer systems until such time as Superfish is able to provide a software build that addresses these issues”
    “As for units already in market, we have requested that Superfish auto-update a fix that addresses these issues.
    Statements like this do not inspire confidence, they have temporarily removed Superfish and have failed to satisfy the millions of customers who already have it installed, illegally. This fails to address why it was ever installed in the first place, what Lenovo got from the deal and if other malware is present on Lenovo computers.

    9
    Install the app to use these features.
    Mute Barry O'Brien
    Favourite Barry O'Brien
    Report
    Feb 20th 2015, 2:14 PM

    G’way with the racism crap. It’s a fact that Chinese companies have been shipping Android phones with pre-installed malware for a while now. Doesn’t mean they were first but it does mean I wouldn’t by a Chinese company’s Android phone. Nothing personal against the Chinese but I don’t trust a company that’s owned by a repressive government who smother their citizens in propaganda and deny them access to any information outside a distorted reality that’s defined by an elite.

    Not to say I trust NSA/GCHQ/[enter other western intelligence agency] any bit either…

    4
    Install the app to use these features.
    Mute Francis Fakeman
    Favourite Francis Fakeman
    Report
    Feb 20th 2015, 8:37 AM

    Guys. Lenovo is possibly the cheapest shittiest Chinese brand of desktop hardware. You get what you pay for.

    42
    Install the app to use these features.
    Mute Jason Bourne
    Favourite Jason Bourne
    Report
    Feb 20th 2015, 9:52 AM

    Consumer wise yes. Enterprise, they were decent until recently.

    20
    Install the app to use these features.
    Mute Weighing Scales
    Favourite Weighing Scales
    Report
    Feb 20th 2015, 9:12 AM

    Poor old Lenova they’ve never been the same since IBM sold them. Used to be brilliant.

    40
    Install the app to use these features.
    Mute Jason Bourne
    Favourite Jason Bourne
    Report
    Feb 20th 2015, 9:49 AM

    Their T530s and W530s are rock solid. Use these at work. But why oh why do they go and screw it up with the new w540/T540p range?

    Crap plastic feel, KB relayout and no actual mouse pad buttons.

    16
    Install the app to use these features.
    Mute Johnny Norton
    Favourite Johnny Norton
    Report
    Feb 20th 2015, 1:28 PM

    I have a w520 for nearly 4 years. It’s still a great spec. i7- 8-32 gigs of ram – 2 gig quadro graphics card. Powers 1 – 3 external monitors. A complete desktop replacement. I use it for heavy work every day and never had one issue and it’s still well able for anything I can throw at it. 6 months ago I extended my warranty from 3 years (included) to five years for 100 euro so its still covered by lenovo. Best purchase I ever made!

    4
    Install the app to use these features.
    Mute Luther Cooper
    Favourite Luther Cooper
    Report
    Feb 20th 2015, 8:34 AM

    LOL! good old Lenovo!!! ring their support ….really helpful!!!

    32
    Install the app to use these features.
    Mute Broken Design
    Favourite Broken Design
    Report
    Feb 20th 2015, 11:20 AM

    What’s with all the Lenovo hate? Bought mine 6 years ago and it still works perfectly, despite the abuse it’s taken!

    24
    Install the app to use these features.
    Mute Tom Feehan
    Favourite Tom Feehan
    Report
    Feb 20th 2015, 8:22 AM

    Lean over

    15
    Install the app to use these features.
    Mute adam murphy
    Favourite adam murphy
    Report
    Feb 20th 2015, 11:25 AM

    I got an Ideapad 4 years back, and apart from some recent problems, it’s never been a problem for me. I was surprised to see so much Lenovo hate here

    12
    Install the app to use these features.
    Mute Jimmy Murphy
    Favourite Jimmy Murphy
    Report
    Feb 20th 2015, 11:02 AM

    Lenovo laptops are useless lumps of shite. I repair laptops & desktops for people all the time and it’s mostly lenovos.
    Avoid them like the plague

    12
    Install the app to use these features.
    Mute Francis Fakeman
    Favourite Francis Fakeman
    Report
    Feb 20th 2015, 8:35 AM

    Here come the Lenovo fanboys. Ffs.

    7
    Install the app to use these features.
    Mute Tweety McTweeter
    Favourite Tweety McTweeter
    Report
    Feb 20th 2015, 8:47 AM

    Faux outrage at a comment that hasn’t been posted yet ?!…. Really?

    62
    Install the app to use these features.
    Mute little jim
    Favourite little jim
    Report
    Feb 20th 2015, 9:38 AM

    I love Len O’Va!
    There, happy now?

    7
    Install the app to use these features.
    Mute John Wheelwright
    Favourite John Wheelwright
    Report
    Feb 20th 2015, 10:09 AM

    IBM support this brand, what more can one say.

    6
    Install the app to use these features.
    Mute Enda Dirrane
    Favourite Enda Dirrane
    Report
    Feb 20th 2015, 9:03 AM

    It’s really a Think bad…

    6
    Install the app to use these features.
    Mute Stephen Boland
    Favourite Stephen Boland
    Report
    Feb 20th 2015, 12:19 PM

    “Levono” Really?! who’s asleep today?

    2
    Install the app to use these features.
    Mute Michele Savage
    Favourite Michele Savage
    Report
    Feb 20th 2015, 9:59 AM

    Not so super then

    1
Submit a report
Please help us understand how this comment violates our community guidelines.
Thank you for the feedback
Your feedback has been sent to our team for review.
JournalTv
News in 60 seconds