Share

US urges Lenovo to remove buggy 'Superfish' program

Boston - The US government has advised Lenovo Group customers to remove Superfish, a program pre-installed on some Lenovo laptops, saying it makes users vulnerable to cyber attacks.

The Department of Homeland Security said in an alert that the program makes users vulnerable to a type of cyber attack known as SSL spoofing, in which remote attackers can read encrypted web traffic, redirect traffic from official websites to spoofs, and perform other attacks.

"Systems that came with the software already installed will continue to be vulnerable until corrective actions have been taken," the agency said.

Adi Pinhas, chief executive of Palo Alto, California-based Superfish, said in a statement that his company's software helps users achieve more relevant search results based on images of products viewed. He said the vulnerability was "inadvertently" introduced by Israel-based Komodia, which built the application described in the government notice.

Komodia CEO Barak Weichselbaum declined comment on the vulnerability.

Lenovo apologised late on Friday in a statement for "causing these concerns among our users" and said that it was "exploring every action we can" to address the issues around Superfish, including offering tools to remove the software and certificate.

Snooping

"We ordered Superfish pre-loads to stop and had server connections shut down in January based on user complaints about the experience. However, we did not know about this potential security vulnerability until yesterday [Thursday]," the Lenovo statement said.

"We recognise that this was our miss, and we will do better in the future. Now we are focused on fixing it," the company said.

Komodia's website says it produces a "hijacker" that allows users to view data encrypted with SSL technology.

"The hijacker uses Komodia's redirector platform to allow you easy access to the data and the ability to modify, redirect, block, and record the data without triggering the target browser's certification warning," according to the site.

Marc Rogers, a researcher with CloudFlare, said that means companies which deploy Komodia technology can snoop on web traffic.

"These guys can do everything from just collect a little bit of marketing information, all the way to building a profile on you and spying on your banking connections," he said. "It's a very dangerous slope."

Rogers said that use of Komodia's technology in other products makes them vulnerable to the same types of attacks as Lenovo's Superfish.

He said other vulnerable products include two parental filters: One from Komodia known as KeepMyFamilySecure and another from Qustodio.

Komodia's Weichselbaum said his company was investigating reports of vulnerabilities in KeepMyFamilySecure.

Qustodio CEO Eduardo Cruz CEO said his company's Windows parental filter was vulnerable and he hoped to push out a fix within a few days.

Lenovo did not disclose how many machines were affected, but said that only machines shipped from September to December of 2014 had been pre-loaded with the vulnerable software.

We live in a world where facts and fiction get blurred
Who we choose to trust can have a profound impact on our lives. Join thousands of devoted South Africans who look to News24 to bring them news they can trust every day. As we celebrate 25 years, become a News24 subscriber as we strive to keep you informed, inspired and empowered.
Join News24 today
heading
description
username
Show Comments ()
Rand - Dollar
19.20
-0.5%
Rand - Pound
23.93
-0.6%
Rand - Euro
20.55
-0.5%
Rand - Aus dollar
12.48
-0.7%
Rand - Yen
0.12
-0.2%
Platinum
913.70
-0.7%
Palladium
1,007.00
-1.9%
Gold
2,320.68
-0.1%
Silver
27.23
-0.3%
Brent Crude
88.42
+1.6%
Top 40
68,574
+0.8%
All Share
74,514
+0.7%
Resource 10
60,444
+1.4%
Industrial 25
104,013
+1.2%
Financial 15
15,837
-0.4%
All JSE data delayed by at least 15 minutes Iress logo
Company Snapshot
Editorial feedback and complaints

Contact the public editor with feedback for our journalists, complaints, queries or suggestions about articles on News24.

LEARN MORE
Government tenders

Find public sector tender opportunities in South Africa here.

Government tenders
This portal provides access to information on all tenders made by all public sector organisations in all spheres of government.
Browse tenders