Lenovo to Stop Pre-Installing 'Adware' on Consumer PCs

Advertisement
By Reuters | Updated: 21 February 2015 12:25 IST

China's Lenovo Group Ltd, the world's largest PC maker, said on Thursday it will no longer pre-install software that cybersecurity experts said was malicious and made devices vulnerable to hacking.

Lenovo had come under fire from security researchers who said earlier on Thursday the company pre-installed a virus-like software from a company called Superfish on consumer laptops that hijacked web connections and allowed them to be spied upon.

Users reported as early as last June that a programme, also called Superfish, was 'adware', or software that automatically displays adverts.

Advertisement

Superfish will no longer be pre-installed and has been disabled on all products in the market since January, when Lenovo also stopped pre-installing the software, said a Lenovo spokesman in an email to Reuters on Thursday. Superfish was included on some consumer notebooks shipped between October and December, he said.

Advertisement

"We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns," the spokesman said. Superfish "does not profile nor monitor user behaviour. It does not record user information. It does not know who the user is. Users are not tracked nor re-targeted... The relationship with Superfish is not financially significant."

On Friday, the Lenovo United States Twitter handle provided instructions on how to remove the Superfish software and root certificate, guiding users to its support forums page.

Advertisement

Robert Graham, CEO of U.S.-based security research firm Errata Security, said Superfish was malicious software that hijacks and throws open encrypted connections, paving the way for hackers to also commandeer these connections and eavesdrop, in what is known as a man-in-the-middle attack.

"This hurts (Lenovo's) reputation," Graham told Reuters. "It demonstrates the deep flaw that the company neither knows nor cares what it bundles on their laptops."

Advertisement

Graham and other experts said Lenovo was negligent, and that computers could still be vulnerable even after uninstalling Superfish. The software throws open encryptions by giving itself authority to take over connections and declare them as trusted and secure, even when they are not.

Graham added that Lenovo's method of removing the root certificate doesn't do so for users utilising the Firefox browser, and provides instructions on how to do it: " For Firefox, click on the main menu "Options", "Advanced", "Certificates". The Certificate Manager pops up. Scroll down, select "Superfish, Inc.", then "Delete or Detrust"."

"The way the Superfish functionality appears to work means that they must be intercepting traffic in order to insert the ads," said Eric Rand, a researcher at Brown Hat Security. "This amounts to a wiretap."

Concerns about cybersecurity have dogged Chinese firms, including telecoms equipment maker Huawei Technologies Ltdn over ties to China's government and smartphone maker Xiaomi Inc over data privacy.

Lenovo commanded one-fifth of the global PC market in the third quarter of 2014, according to data research firm IDC. 

© Thomson Reuters 2015

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Adware, Apps, Laptops, Lenovo, PC, Superfish
Advertisement

Related Stories

Popular Mobile Brands
  1. Best Diwali 2025 Wishes, Quotes, and Facebook Statuses to Share
  1. Mysterious Asteroid Impact Found in Australia, But the Crater is Missing
  2. Thanal Comes to OTT: Everything You Need to Know About This Tamil Action Thriller
  3. Madam Sengupta Is Now Streaming: Know Where to Watch This Bangla Crime Thriller
  4. Ryugu Samples Reveal Ancient Water Flow on Asteroid for a Billion Years
  5. Scientists Create Most Detailed Radio Map of Early Universe Using MWA
  6. Mayor of Kingstown Season 4 OTT Release: Know When, Where to Watch Jeremy Renner's Crime Drama
  7. Our Fault Is Streaming Now: Know All About This Gabriel Guevara and Nicole Wallace Starrer
  8. The Conjuring: Last Rites Is Now Streaming Online: Know Where to Watch the Latest Installment from the Horror Franchise
  9. Delhi Crime Season 3 OTT Release: Know When to Watch This Shefali Shah Thriller Series
  10. Vast Space to Launch Haven-1, the World’s First Private Space Station in 2026
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.