Advertisement

US advises Lenovo to remove Superfish program from laptops

The U.S. government on Friday advised Lenovo Group Ltd customers to remove a "Superfish," a program pre-installed on some Lenovo laptops, saying it makes users vulnerable to cyberattacks.

Advertisement
FP Archives|Feb 22, 2015, 13:15:54 IST

The U.S. government on Friday advised Lenovo Group Ltd customers to remove a "Superfish," a program pre-installed on some Lenovo laptops, saying it makes users vulnerable to cyberattacks.The Department of Homeland Security said in an alert that the program makes users vulnerable to a type of cyberattack known as SSL spoofing, in which remote attackers can read encrypted web traffic, redirect traffic from official websites to spoofs, and perform other attacks."Systems that came with the software already installed will continue to be vulnerable until corrective actions have been taken," the agency said.Adi Pinhas, chief executive of Palo Alto, California-based Superfish, said in a statement that his company's software helps users achieve more relevant search results based on images of products viewed. He said the vulnerability was "inadvertently" introduced by Israel-based Komodia, which built the application described in the government notice.Komodia CEO arak Weichselbaum declined comment on the vulnerability. Komodia's website says it produces a "hijacker" that allows users to view data encrypted with SSL technology."The hijacker uses Komodia’s redirector platform to allow you easy access to the data and the ability to modify, redirect, block, and record the data without triggering the target browser’s certification warning," according to the site.Marc Rogers, a researcher with CloudFlare, said that means companies which deploy Komodia technology can snoop on web traffic."These guys can do everything from just collect a little bit of marketing information, all the way to building a profile on you and spying on your banking connections," he said. "It's a very dangerous slope."Rogers said that use of Komodia's technology in other products makes them vulnerable to the same types of attacks as Lenovo's Superfish. He said other vulnerable products include two parental filters: One from Komodia known as KeepMyFamilySecure and another from Qustodio.Komodia's Weichselbaum said his company was investigating reports of vulnerabilities in KeepMyFamilySecure. Qustodio CEO Eduardo Cruz Chief Executive said his company's Windows parental filter was vulnerable and he hoped to push out a fix within a few days.Lenovo did not disclose how many machines were affected, but said that only machines shipped from September to December of last year had been pre-loaded with the vulnerable software.Affected Lenovo products include laptops in its Yoga, Flex and MiiX lines as well as its E, G, U, Y and Z series, according to the company's support website.Reuters

Advertisement
Handpicked stories, in your inbox
Global stories. Indian perspective. Zero noise.
No Spam. Unsubscribe Any Time.
First Published:Feb 22, 2015, 13:15:54 IST
Advertisement
Advertisement
Trending Stories

China's Kimi K3 challenges US AI leaders with frontier-level performance at lower cost

Chinese artificial intelligence startup Moonshot AI has unveiled its latest open-weight AI model, Kimi K3, with early results suggesting it could compete with some of the world's most advanced AI systems developed by leading US companies
2 min read
Advertisement
Advertisement
Up Next