The Password Was "komodia"

The Password Was "komodia"

Tech News lenovo security ssl superfish

My mother-in-law bought a new laptop back in December, a Lenovo, cheap enough that she got change back from $400 at Best Buy, and for two months it sat there doing normal laptop things until last weekend when she called me because "the internet looks weird." Ads everywhere. Boxes popping up over Google search results that had nothing to do with Google. I drove over Saturday afternoon expecting the usual toolbar garbage, maybe a browser hijack, something I could fix in twenty minutes and be home in time for dinner.

It was not the usual toolbar garbage.

It was Superfish, the adware thats been all over the tech press this week, and once I actually read what it does I stopped being annoyed and got genuinely worried. This isnt some browser extension injecting banner ads into web pages. Superfish installs its own self-signed root certificate into Windows, at the operating system level, so it can sit between the browser and every HTTPS connection and quietly re-sign the traffic as if it came from Superfish instead of the real site. Your bank's padlock icon still shows up green. Your browser still says the connection is secure. It just isnt, not really, because the trust chain now runs through a certificate Lenovo shipped on every one of these machines with the exact same private key.

That last part is the detail that got me. Researchers pulled the private key off the certificate within a few hours of this becoming public, and it turns out the passphrase protecting it was "komodia," the name of the company that makes the SSL-hijacking library Superfish uses under the hood. So anyone who wanted to could build a fake certificate for literally any website, sign it with that key, and a Lenovo laptop running Superfish would treat it as trusted. No warnings, no red flags in the browser. A coffee shop wifi network run by somebody with bad intentions and a Lenovo victim sitting nearby is a genuinely bad afternoon waiting to happen.

DHS put out an advisory about it Friday telling people to check for the certificate and rip it out, which is not a sentence I expected to type about a laptop ad program. Lenovo's initial response, from back in January when people first started noticing this, was basically that it wasnt a security concern, just an ad thing to help with product discovery, which is the kind of statement that ages badly within about three weeks.

Getting it off her machine took longer than I wanted. Uninstalling Superfish through the normal Windows uninstaller does not remove the root certificate, it just takes away the visible program and leaves the actual security hole sitting in the certificate store. I ended up going into certmgr.msc by hand, hunting through Trusted Root Certification Authorities for "Superfish Inc," and deleting it there, then double checking with one of the little browser test pages that started popping up that week to confirm HTTPS on her machine actually meant something again. Lenovo has since put out an actual removal tool that does this properly, which Id just use if I were doing this again, because poking around in a certificate store by hand on someone elses computer is not a relaxing way to spend a Saturday.

What bugs me isnt really that Superfish existed. Shady ad software has existed forever and will keep existing. Its that a company the size of Lenovo, shipping millions of consumer laptops, apparently either didnt understand or didnt care what installing a shared root certificate actually does to every one of those machines security. Thats not a rounding error. Preloaded junk on a new laptop is annoying on a normal day. Preloaded junk that breaks the padlock icon for a couple million people is a different category of problem, and I dont think "helping with product discovery" gets anywhere near covering it.

Also, separate complaint, not really related: why do these Best Buy checkout people always try to upsell the extended warranty on a $400 laptop like its a car. My mother-in-law almost bought a three year plan for more than the laptop cost. Thats its own scandal, just a smaller one.

Anyway, if youve got a Lenovo bought sometime in that fall or winter window and havent checked, it takes about five minutes with their removal tool. Worth doing before you do anything involving a password.