So Lenovo spent the back half of last week apologizing, and honestly I've read the whole Superfish mess about four times now trying to fully understand it, and each time I get a little angrier.
Quick recap in case you were off the internet for a few days (lucky you): starting sometime last fall, Lenovo was shipping a bunch of its consumer laptops with a piece of adware called Superfish Visual Discovery preinstalled. Superfish didn't just inject ads into your browsing, which would be annoying but ordinary. It installed its own self-signed root certificate system-wide so it could crack open HTTPS traffic and slip ads into encrypted pages too. Your bank's padlock icon, Gmail, whatever — Superfish could sit in the middle of it. And then it turned out the private key for that certificate was the same on every single affected machine, and a security researcher named Robert Graham cracked the password protecting it in about three minutes. It was "komodia," by the way, which is also the name of the shady little SSL-hijacking library Superfish was built on. Once that key is public, anyone on your coffee shop wifi can forge a certificate for any site they like and your laptop will trust it completely. Lenovo put out a statement and a removal tool over the weekend, US-CERT issued an alert, and there's now a small industry of "am I infected" web checkers going around.
I don't own a Lenovo, so I wasn't personally affected, but it rattled me enough that I finally did something I've been putting off for probably two years: I sat down last night and turned on two-factor authentication everywhere I could. If you've been putting it off too, here's what I actually did, in the order I did it, because I think the order matters more than people admit.
1. Get an authenticator app first, before you turn anything on. I went with Google Authenticator on my phone, mostly out of laziness since I already had a Google account tied to everything. Authy is the other one people recommend and it's genuinely nicer looking and lets you back up your codes to the cloud, which Google Authenticator infamously does not. If you lose your phone with plain Google Authenticator on it and didn't save your backup codes somewhere, you are in for a very bad afternoon. Ask me how I know. (I don't actually know from firsthand experience, I just have a friend who does, and he was not fun to be around that week.)
2. Start with email, not social media. Your email is the master key to basically every password reset flow on the internet. Turn on 2-Step Verification in Gmail settings under Security first. It'll walk you through scanning a QR code with the authenticator app, then give you ten single-use backup codes. Print those out. Actually print them, don't just screenshot them onto the same phone that could get lost or stolen along with everything else.
3. Then do Dropbox, then your password manager. I use LastPass, and turning on their two-factor option took maybe four minutes. If you're not using a password manager at all yet, that's honestly the bigger fix here, bigger than 2FA even. Reusing passwords is still the number one way people get burned, full stop. I was on 1Password for a while and liked it fine, switched to LastPass mostly for the browser extension being a little smoother on my setup, though I'll admit the LastPass icon design has always bugged me a little, it looks like a stopwatch had a baby with a padlock.
4. Skip SMS-based codes when an app option exists. A lot of sites default to texting you a code, and it works, but your phone number can be ported or intercepted in ways your phone itself generally can't. Use the app-based option whenever it's on the menu.
None of this stops something like Superfish specifically, since that's a certificate trust problem happening at the OS level, not a password problem. But it does mean that if one site gets breached, or one password leaks in some dump on a forum somewhere, the damage stops at that one account instead of cascading into your whole digital life. Took me under an hour total across four accounts. I'd been telling myself it would be a whole ordeal for literally years for no good reason.