Superfish and the Same Old Bloatware Problem

Superfish and the Same Old Bloatware Problem

Tech News bloatware https lenovo security superfish

So this week I finally got around to setting up my mom's new laptop — a Lenovo, because she saw one at Costco and the price was right — and about ten minutes into wiping the crapware off it I remembered why I've hated doing this exact chore for about a decade now. Except this time it wasn't just the usual junk. It was Superfish.

If you haven't been following this, here's the short version. Lenovo had been shipping a bunch of its consumer laptops (dating back to at least September) with a piece of adware called Superfish preinstalled. Its whole job was to inject extra shopping ads into your browser based on images on pages you're looking at. Annoying on its own, sure, plenty of laptops ship with garbage toolbars and trial antivirus nagware. But Superfish did something a lot worse to pull this off: it installed its own self-signed root certificate and used it to intercept HTTPS traffic, meaning it was doing a man-in-the-middle on every "secure" connection those laptops made. Your bank's padlock icon, your email login, all of it was passing through Superfish's certificate instead of the real one.

That's already bad. What made it so much worse, and honestly the part that stuck with me more than the ad-injection angle, is that every single Superfish install used the same private key, and the password protecting that key got cracked within about a day of researchers looking at it. Turned out to be "komodia," the name of the company that made the software development kit Superfish was built on. Once that was out there, anyone on the same coffee shop wifi as an affected laptop could spoof basically any HTTPS site to it and the browser would show a trusted connection the whole time. Errata Security's Rob Graham was one of the people who dug into it and didn't have much trouble.

Lenovo's response has been kind of a mess, honestly. First there was a statement downplaying it, then an actual apology, then a removal tool, and now Microsoft has pushed an update to Windows Defender so it'll flag and pull Superfish itself since apparently that's faster than waiting on everyone to run Lenovo's tool. McAfee and a few other AV vendors are doing the same. If you've got a Lenovo bought recently, or you're doing tech support for a relative like I was this weekend, it's worth checking Windows for anything called Superfish or VisualDiscovery and yanking the certificate out of the trusted root store manually if the automated tools don't catch it.

Here's my actual gripe though, and it's bigger than one bad decision by one company. I have set up probably thirty laptops for family and friends over the years and I cannot remember a single one, from any manufacturer, that didn't arrive with something I had to rip out before I'd let a person I care about actually use it. Trial McAfee. Random toolbars. "PC optimization" tools that are themselves the thing slowing the PC down. It's been true of HP, it's been true of Dell, it's been true of pretty much everyone selling Windows machines at retail, because OEMs get paid by these companies to preinstall this stuff and apparently that money matters more than not compromising the machine's security model. Superfish is just the one that went so far it broke HTTPS for everybody, which is why it's getting the attention the toolbars never did. But the incentive that put it there isn't new and isn't going away just because this one blew up.

My mom's laptop is clean now. It took me a solid forty minutes between the standard bloat and then double checking the cert store for the Superfish stuff on top of it, and I still felt like I should go back and check again. That's a bad place to be with a machine somebody's about to start banking on.

If you're the one doing tech support duty in your family this week, same as always, it's you and nobody else. Check for it.