I spent about an hour and a half Saturday afternoon at my uncle's kitchen table with his Lenovo laptop open, a USB stick full of removal tools, and a growing sense that this whole preloaded-software business needs to just stop.
You've probably seen the headlines by now: Lenovo shipped a bunch of consumer laptops since last September with something called Superfish VisualDiscovery baked in, and it turns out the thing was doing something way worse than showing you extra shopping ads. It was installing its own self-signed root certificate so it could get inside your encrypted HTTPS traffic and inject ads into pages that are supposed to be locked down (your bank, your email, whatever). And because the software used the same private key on every single affected machine, the second somebody dug the key out, which took approximately no time at all, every Superfish laptop on earth became trivially easy to man-in-the-middle.
The detail that really got me, and the actual reason I ended up at my uncle's table in the first place, is that the password protecting that private key was "komodia," which is literally just the name of the company (Komodia) that made the interception library Superfish was built on. Rob Graham over at Errata Security had it cracked in about three hours using a tool called John the Ripper, mostly because he guessed right almost immediately. Three hours. For software installed at the factory on machines people use for online banking.
Anyway, my uncle bought a Yoga 2 back in November, loves it, uses it for everything including his taxes, and had no idea any of this was happening until I called him Friday night and more or less told him to stop using it until I could come over. He was annoyed. Not at Lenovo, at me, for "being paranoid," which is a whole separate thing I could probably write a post about. Getting a normal person to care about a certificate authority is like getting them to care about the plumbing behind their walls. It only matters once it's actively flooding the kitchen.
The actual fix wasn't hard once I was there. Lenovo had already put out a removal tool by Friday, and Microsoft pushed a Windows Defender signature update that flags and strips the certificate too, so between those two and manually checking his certificate store to make sure nothing was left behind, we were done in about twenty minutes. The other hour and change was me explaining what a certificate even is, why "https" matters, and no, this doesn't mean somebody stole his social security number, and yes, he should still be annoyed about it.
What bugs me isn't really Superfish specifically. Adware is adware, there's always some garbage preloaded on new Windows machines, that's basically been true since I started building PCs for people back around 2004. What bugs me is that a company the size of Lenovo apparently didn't do enough due diligence to notice their ad-injection vendor was breaking HTTPS for every single customer who bought the laptop. Lenovo's official line so far has been something about "enhancing the shopping experience," which is the kind of sentence that could only get written by someone who never once opened a legal pad and thought, wait, are we breaking encryption here.
I don't think this story is finished yet either. US-CERT put out a formal alert about it this week, and I'd genuinely bet money there's a class action lawsuit with Lenovo's name on it before the year's out. If you or anyone you know bought a Lenovo consumer laptop (not a ThinkPad, this seems to mostly hit the G, Yoga, and Flex lines) between September and now, it's worth five minutes to go check. Lenovo's support page has removal instructions up, and if you're on Windows with current Defender definitions it may have already been handled for you without you noticing.
Also, separate note to future me: stop being the free IT department for the entire extended family. I write some version of this sentence every year and I never learn a thing from it.