Hacker News new | ask | show | jobs
by autoexec 1405 days ago
I'd start here: https://en.wikipedia.org/wiki/Lenovo#Security_and_privacy_in...

Superfish was bad enough, but once the public became aware that the malware existed and was so insecure that it made their devices vulnerable to be hacked Lenovo provided people with a fix to remove the malware, but it left the security vulnerability that the malware introduced to the system in place leaving everyone to think they solved the problem when they were still vulnerable. People had to track down news articles and social media posts for information on how to correct the problem until Lenovo updated their instructions. (https://arstechnica.com/information-technology/2015/02/how-t...)

Further reading: https://www.eset.com/int/about/newsroom/press-releases/resea...

https://www.osnews.com/story/30736/lenovo-companies-working-...

https://news.ycombinator.com/item?id=18025645

https://www.theregister.com/2022/07/14/lenovo_uefi_vuln/

https://www.bleepingcomputer.com/news/security/lenovo-discov...

https://wccftech.com/lenovo-fingerprint-scanner-hardcoded-pa...

https://grahamcluley.com/lenovo-used-12345678-hard-coded-pas...