|
Alan Rockefeller
Mycologist

Registered: 03/10/07
Posts: 48,392
Last seen: 2 days, 1 hour
|
New Lenovo computers come with a huge security hole
#21308414 - 02/21/15 01:28 PM (9 years, 2 months ago) |
|
|
|
Warrior




Registered: 05/13/11
Posts: 1,010
Loc: DedSec fsociety
|
Re: New Lenovo computers come with a huge security hole [Re: Alan Rockefeller]
#21311210 - 02/21/15 10:30 PM (9 years, 2 months ago) |
|
|
Lenovo has pre-installed Superfish on PCs since at least mid-2014. The following laptop models may be affected:
G Series: G410, G510, G710, G40-70, G50-70, G40-30, G50-30, G40-45, G50-45 U Series: U330P, U430P, U330Touch, U430Touch, U530Touch Y Series: Y430P, Y40-70, Y50-70 Z Series: Z40-75, Z50-75, Z40-70, Z50-70 S Series: S310, S410, S40-70, S415, S415Touch, S20-30, S20-30Touch Flex Series: Flex2 14D, Flex2 15D, Flex2 14, Flex2 15, Flex2 14(BTM), Flex2 15(BTM), Flex 10 MIIX Series: MIIX2-8, MIIX2-10, MIIX2-11 YOGA Series: YOGA2Pro-13, YOGA2-13, YOGA2-11BTM, YOGA2-11HSW E Series: E10-30
THIS site will quickly show you whether or not your PC is affected.
THIS link will show you a step-by-step guide to manually remove it.
Otherwise, update and run Mocrosoft Windows Defender and it'll remove it automatically.
--------------------
Play Clash of Clans? Join the Shroomery clan!
|
Byrain

Registered: 01/07/10
Posts: 9,664
|
Re: New Lenovo computers come with a huge security hole [Re: Warrior]
#21312108 - 02/22/15 09:23 AM (9 years, 2 months ago) |
|
|
Just reformat the windows partition and put GNU/Linux or BSD on it, problem solved.
|
Warrior




Registered: 05/13/11
Posts: 1,010
Loc: DedSec fsociety
|
Re: New Lenovo computers come with a huge security hole [Re: Byrain]
#21314500 - 02/22/15 07:03 PM (9 years, 2 months ago) |
|
|
The antivirus Lenovo bundles on their laptops now detects Superfish, software they also bundled.
That's kind of awkward.lol
--------------------
Play Clash of Clans? Join the Shroomery clan!
|
Bacchus
Lurker




Registered: 10/10/06
Posts: 914
Loc: ::1
|
Re: New Lenovo computers come with a huge security hole [Re: Warrior]
#21329695 - 02/25/15 06:27 PM (9 years, 2 months ago) |
|
|
If you're interested in the nuts and bolts, then click the "a single self-signed root certificate" link, and you'll get to the good stuff.
--------------------
Living on a no-Flash diet is way easier than you think. Give it a shot.
|
Andjew
.


Registered: 09/08/13
Posts: 470
|
Re: New Lenovo computers come with a huge security hole *DELETED* [Re: Byrain]
#21345264 - 02/28/15 05:42 PM (9 years, 2 months ago) |
|
|
Post deleted by AndjewReason for deletion: Redacted for job security
-------------------- -
|
Bacchus
Lurker




Registered: 10/10/06
Posts: 914
Loc: ::1
|
Re: New Lenovo computers come with a huge security hole [Re: Andjew]
#21346048 - 02/28/15 09:16 PM (9 years, 2 months ago) |
|
|
That solves the problem for one person, sure. But the big fuck-up here is that so many people now have the same komodia public key in their root stores, and the matching private key is open to the world. You can find it on paste bin. The passphrase is "komodia" 
Everyone with this on their PC is vulnerable to having their secure connections intercepted by a man-in-the-middle (stay away from coffee shops...)
You knew that, I know. I guess I just felt like summarizing for the non-RTFMers amongst us.
--------------------
Living on a no-Flash diet is way easier than you think. Give it a shot.
|
Byrain

Registered: 01/07/10
Posts: 9,664
|
Re: New Lenovo computers come with a huge security hole [Re: Bacchus]
#21347219 - 03/01/15 08:48 AM (9 years, 2 months ago) |
|
|
Who the hell uses Komodia for ssl on Gnu/linux or bsd? Lol
|
Alan Rockefeller
Mycologist

Registered: 03/10/07
Posts: 48,392
Last seen: 2 days, 1 hour
|
Re: New Lenovo computers come with a huge security hole [Re: Byrain]
#21347501 - 03/01/15 09:57 AM (9 years, 2 months ago) |
|
|
Quote:
Byrain said: Who the hell uses Komodia for ssl on Gnu/linux or bsd? Lol
Who the hell uses Gnu/linux or BSD? The two OS's combined have 2% of the market share according to Wikipedia. I am using Linux now, but huge numbers of people remain affected by this.
|
Byrain

Registered: 01/07/10
Posts: 9,664
|
Re: New Lenovo computers come with a huge security hole [Re: Alan Rockefeller]
#21348145 - 03/01/15 12:55 PM (9 years, 2 months ago) |
|
|
And the freedom to not be affected by this (Among numerous other issues) is available to pretty much everyone with an useful internet connection. What distro are you using now? I'm using Slackware-current.
|
Alan Rockefeller
Mycologist

Registered: 03/10/07
Posts: 48,392
Last seen: 2 days, 1 hour
|
Re: New Lenovo computers come with a huge security hole [Re: Byrain]
#21352929 - 03/02/15 05:28 PM (9 years, 2 months ago) |
|
|
I am using Debian on some machines and Ubuntu on others.
|
|