So I was helping my cousin shop for a laptop over Christmas, and she almost walked out of Best Buy with a Lenovo Flex. Cute little convertible, decent price, nothing wrong with it on paper. I'm glad now that she ended up going with something else, because it turns out a chunk of Lenovo's consumer lineup from last September through this month shipped with something called Superfish sitting on the hard drive before you even opened the box.
If you haven't been following this, the short version is ugly. Superfish is adware that injects extra ads into your browsing by sitting between you and every website you visit, including ones over HTTPS, the supposedly-secure connections your bank and your email use. To pull that off it installs its own self-signed root certificate on your machine so it can pretend to be any site it wants. Fine in theory, except researchers found the private key for that certificate was the same on every single affected laptop. Same key, every machine. Which means anyone who bothered to extract it (and people did, within hours of the story breaking) could forge a certificate for literally any HTTPS site and intercept traffic on any Lenovo laptop with Superfish installed, on public wifi, at a coffee shop, wherever. That's not "we sold you some annoying pop-ups." That's "we shipped you a security hole with a bow on it."
Lenovo's initial response was the kind of corporate non-answer that makes everything worse. They downplayed it for a day or two before admitting it was a real problem, and by the 20th they'd said they'd stop preloading it going forward and put out a removal tool. Microsoft quietly updated Windows Defender to detect and strip it out, which tells you how seriously they were taking it. US-CERT, which is the part of the federal government that issues warnings about this stuff, put out an alert telling people to remove it. And I've already seen chatter about a class action lawsuit forming, which, yeah, I'd be surprised if that doesn't happen.
Here's the thing that actually gets me though, more than the Superfish specifics. This is what happens when "we get paid to preload junk on your new computer" is a normal, accepted line item in a laptop manufacturer's business model. Superfish is the extreme, dangerous version of a problem that's been sitting in plain sight for years: the McAfee trial that nags you every time you boot, the random toolbar, the "PC optimizer" that's really just a nag screen for a paid version, the OEM's own bloated media player nobody asked for. Companies get paid by third parties to cram this stuff onto machines before they ever reach a store shelf, and normally the worst outcome is that your laptop feels sluggish out of the box. This time the worst outcome was "your bank login can be intercepted." Same incentive structure, wildly different stakes, and nobody stopped to ask where the line was until it blew up in public.
I've had a personal rule for years now that I wipe and reinstall Windows on literally every new machine before I do anything else with it, mine or a family member's. I used to think I was being a little paranoid about it, or at least that it was overkill for anyone who isn't, you know, me. After this week I don't think that anymore. If your only defense against a certificate-hijacking vulnerability shipped from the factory is "well, I happen to nuke the install," that's not really a defense that scales to normal people, and it shouldn't have to be one.
Separate note, because I know it's the story everyone's actually talking about this week: yes, the FCC vote on net neutrality happened Thursday. I'm not going to do the whole "here's what Title II means" post because by the time this goes up you'll have read six of those already from six other places, and I don't have anything to add that a hundred other sites haven't already said better. I just wanted it on the record that I noticed.
Anyway. If you've got a Lenovo laptop bought between last fall and now, go check for Superfish. It's a five minute job and there's a removal tool linked from about every tech site this week. Worth the five minutes.