Sunday, February 22, 2015

Chinese Lenovo installs spyware that allows a loophole … – Slate.fr

Some manufacturer’s computers contain adware by default. Not only advertising inserts in your Internet navigation, but it also creates its own security certificates, which puts your secure connection at risk.

We knew adware (or adware) that is installed by mistake and come to rot your Internet searches by inserting constantly advertising. Here is the adware preinstalled in some computers the Chinese Lenovo.

As explained myce specialized site, many Lenovo machine users complain that the builder would “pre-installed the Superfish adware on their computers. Superfish is hiding in Internet Explorer and Google Chrome and injects advertisements on Web pages. Superfish is the default background on affected systems. It is likely that Lenovo installs adware for several months on its devices. “

Here are two screenshots Google search. On the left, a search without adware, right the results proposed by the adware installed on some Lenovo devices. We see that it is not the same as those offered by Google Ads:

Screenshot Slate.fr and iknorr. The strapline “Visual Search Results” are identified and the words “Powered by …”

Clearly, a pre-installed by the manufacturer software insert advertising in your web navigations.

As noted by The Next Web, a director of Lenovo communities, Mark Hopkins, had already responded to the questions of users angered by the appearance of pop -UPS and other non-desired actions.

At the end of January, a manufacturer of forums, he was then justified the presence of adware that would help “users find and discover products” . Mark Hopkins had also explained that Superfish was temporarily removed from the aircraft and indicated that automatic update would be in place for those on which it was installed. Asked by the Guardian, Lenovo made the same remarks

But this is not the biggest problem, as The Next Web raises. By multiple users the adware installs its own security certificates “which allows it to allow the software to take a look at your secure connections, such as when you visit your bank’s website,” .

A user is well noted using screenshots that Superfish “pirate all your secure web connections (SSL / TLS).”

So some private data (such as your passwords) were within the reach of Superfish.

In general, this is called an attack of the middle man and we hear when hacking.

Clubic explains however that manipulation allows departing avoid installing it.

 

“The user has the option to refuse the setting of this program by clearing a small box when it lights up for the first time its new PC, but obviously pay attention to little details like that . “

 

And, if you could not avoid it, “It is very easy to uninstall Superfish. Here is also a video that explains how to do “

In addition, Microsoft says on its website how to manage their certificates if you think your computer is part of those involved.

To remove the SSL certificate Superfish on Windows 7 follow these instructions, Inc. Superfish find and delete

As a reminder, only in 2014. Lenovo sold more than 59 million PCs, making it the market leader, according to Gartner.

Update February 19: Lenovo released a statement on his website, where he states that Superfish has been disabled for products placed on the market since January 2015. He gives all models on which Superfish has been installed and also has a tutorial to remove it.

LikeTweet

No comments:

Post a Comment