📎 AI Summary:
The forum thread discusses concerns about Lenovo preinstalling adware, specifically Superfish, which hijacks encrypted HTTPS sessions and creates security vulnerabilities that could facilitate man-in-the-middle attacks. The original poster shares a related article and a guide on removing the adware, prompting others to express surprise and concern about Lenovo’s history with potential spying and security issues dating back years. Overall, the discussion reflects apprehension over Lenovo’s security practices and warnings about additional risks associated with their devices.

Sonny

Fantastic Member
Member details
Joined
Nov 17, 2009
Messages
1,386
Thread Author #1
Lenovo is selling computers that come preinstalled with adware that hijacks encrypted Web sessions and may make users vulnerable to HTTPS man-in-the-middle attacks that are trivial for attackers to carry out, security researchers said.

http://arstechnica.com/security/201...-middle-adware-that-breaks-https-connections/
 

ussnorway

Windows Forum Team
Staff member
Member details
Joined
May 22, 2012
Messages
4,599
Thanks for the post Sonny... I'm not a fan of Lenovo but this does surprise me.
 

Sonny

Fantastic Member
Member details
Joined
Nov 17, 2009
Messages
1,386
Thread Author #4
Thanks ussnorway, I am also surprised by it.
 

Trouble

Noob Whisperer
Member details
Joined
Nov 30, 2009
Messages
13,723
This isn't the first time that Lenovo has been suspected of this type of behavior.
All you have to do is Google, Lenovo + Spying + Firmware
and you'll find articles dating all the way back to 2006, relating concerns from various Government Agencies in the U.S., Australia, the U.K., and others who have express concerns over various potential such inclusions in Lenovo products.
Personally... I'd never own one. Which is a shame, as they make some pretty nice devices.
 

Trouble

Noob Whisperer
Member details
Joined
Nov 30, 2009
Messages
13,723
Some additional information regarding this type of attack vector and how you may be otherwise exposed.
http://arstechnica.com/security/201...geek&utm_medium=email&utm_campaign=newsletter
AND
http://www.howtogeek.com/210265/dow...bundle-superfish-style-https-breaking-adware/

More PITA problems to keep your eye out for.