US Government Urges Lenovo to Remove Superfish Software From Laptops

Advertisement
By Reuters | Updated: 21 February 2015 10:39 IST
The US government on Friday advised Lenovo Group Ltd customers to remove "Superfish," a program pre-installed on some Lenovo laptops, saying it makes users vulnerable to cyberattacks.

The Department of Homeland Security said in an alert that the program makes users vulnerable to a type of cyberattack known as SSL spoofing, in which remote attackers can read encrypted web traffic, redirect traffic from official websites to spoofs, and perform other attacks.

"Systems that came with the software already installed will continue to be vulnerable until corrective actions have been taken," the agency said.

Advertisement

Adi Pinhas, chief executive of Palo Alto, California-based Superfish, said in a statement that his company's software helps users achieve more relevant search results based on images of products viewed. He said the vulnerability was "inadvertently" introduced by Israel-based Komodia, which built the application described in the government notice.

Komodia CEO Barak Weichselbaum declined comment on the vulnerability.

Advertisement

Lenovo apologized late on Friday in a statement for "causing these concerns among our users" and said that it was "exploring every action we can" to address the issues around Superfish, including offering tools to remove the software and certificate.

"We ordered Superfish pre-loads to stop and had server connections shut down in January based on user complaints about the experience. However, we did not know about this potential security vulnerability until yesterday (Thursday)," the Lenovo statement said.

Advertisement

"We recognize that this was our miss, and we will do better in the future. Now we are focused on fixing it," the company said.

Komodia's website says it produces a "hijacker" that allows users to view data encrypted with SSL technology.

Advertisement

"The hijacker uses Komodia's redirector platform to allow you easy access to the data and the ability to modify, redirect, block, and record the data without triggering the target browser's certification warning," according to the site.

Marc Rogers, a researcher with CloudFlare, said that means companies which deploy Komodia technology can snoop on web traffic.

"These guys can do everything from just collect a little bit of marketing information, all the way to building a profile on you and spying on your banking connections," he said. "It's a very dangerous slope."

Rogers said that use of Komodia's technology in other products makes them vulnerable to the same types of attacks as Lenovo's Superfish.

He said other vulnerable products include two parental filters: One from Komodia known as KeepMyFamilySecure and another from Qustodio.

Komodia's Weichselbaum said his company was investigating reports of vulnerabilities in KeepMyFamilySecure.

Qustodio CEO Eduardo Cruz Chief Executive said his company's Windows parental filter was vulnerable and he hoped to push out a fix within a few days.

Lenovo did not disclose how many machines were affected, but said that only machines shipped from September to December of last year had been pre-loaded with the vulnerable software.

Affected Lenovo products include laptops in its Yoga, Flex and MiiX lines as well as its E, G, U, Y and Z series, according to the company's support website.

© Thomson Reuters 2015
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Adwares, Apps, Cyber, Laptops, Lenovo, PC, Superfish, US
Advertisement

Related Stories

Popular Mobile Brands
  1. Tecno Camon 50 Ultra 5G Sale Begins in India Today
  2. Redmi Note 17 Pro Max Listed on NBTC Website Ahead of Imminent Launch
  3. Samsung Galaxy Z Fold 8 Ultra Could Cost More Than Expected, Listing Suggests
  4. Dell Alienware 16X Aurora Launched in India Alongside Alienware Area-51 Series
  5. These OnePlus Smartphones Could Receive the ColorOS 17 Update in India
  6. OnePlus N6x Design, Colour Options Teased Ahead of India Launch
  7. Oppo Find X10 Series Specifications Leak Online
  1. Offline UPI Payments With NFC Support Could Launch in India Soon
  2. Samsung Galaxy S26 Ultra's Privacy Display Feature Gets a Major Upgrade in One UI 9 Beta
  3. OnePlus N6x Design, Colour Options Teased in New Marketing Material Ahead of Imminent Launch in India
  4. OnePlus 11, Nord 4, and Newer Models Tipped to Receive the Android 17-Based ColorOS 17 Update in India
  5. Redmi Note 17 Pro Max Appears on Thailand's NBTC Certification Database, Might Launch Soon
  6. Apple’s First Foldable iPhone Reportedly Appears in iOS 27 Beta Code With a Multi-Battery Setup
  7. X for Android App Undergoes Major Design Overhaul, Enhanced Performance and Reliability
  8. Samsung Galaxy Buds Able to Reportedly Skip Galaxy Unpacked Launch; Could Debut in October
  9. Dell Alienware 16X Aurora, Alienware 16 Area-51 and Alienware 18 Area-51 Launched in India: Price, Specifications
  10. Samsung Galaxy A55, Galaxy A35 One UI 9 Test Builds Reportedly Spotted Ahead of Android 17 Rollout
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.