Showing posts with label Lenovo. Show all posts
Showing posts with label Lenovo. Show all posts

Tuesday, 24 October 2017

Lenovo Provides Computers With FIDO Authenticators



Lenovo has provided various computer models of so-called FIDO authenticators that let users login their accounts via a fingerprint scan or click on a prompt on the screen. The Fast IDentity Online (FIDO) Alliance has set itself the goal of replacing the password with authentication methods that are "safer and user-friendly."

Lenovo is one of the FIDO members, among other things, Google, Microsoft, MasterCard and PayPal. The parties involved develop products and services that make use of the FIDO protocol. This would automatically recognize devices that support FIDO and allow users to replace passwords by another authentication method.

Lenovo now claims that it is the first PC manufacturer to integrate directly into Windows computers by FIDO certified authenticators. Instead of a password to log in, users can choose from an alternative. For example, a fingerprint scan can be logged through the Universal Authentication Framework (UAF). In addition, the system also supports Universal 2nd Factor (U2F).

In case a user has enabled two-factor authentication for his account, it is no longer necessary to enter a separate security key or SMS. The two-factor authentication is built directly into the computer. In the case of two-factor authentication via U2F, users get a prompt to confirm, after which they are logged in to their account. This login method is supported by Google, Facebook and Dropbox.

To support UAF and U2F, Lenovo uses Intel Online Connect and Intel Software Guard Extensions (Intel SGX) on the latest Intel processors. The functionality will be delivered with different computer models and available for all models delivered. Intel Online Connect is available for download from Lenovo's website and will be available through Lenovo System Update and Lenovo App Explorer.

Wednesday, 25 November 2015

Lenovo Used Insecure Password For Admin Account


Computer manufacturer Lenovo has released an update to the System Update tool that fixes two critical vulnerabilities could allow a local attacker to gain system or administrator rights. The software is installed on most Lenovo computers and checks for new versions of drivers and other software. Using the software, users can also download and install updates.

The first issue (pdf) in the System Update tool concerned the temporary system administrator account that Lenovo created.This account was generated in a predictable name and insecure password, which allows a local user could then gain admin privileges. The second problem (pdf) concerned a legal problem which allows a local unprivileged user could execute Windows commands with system privileges.

Both vulnerabilities were discovered by security firm IOActive in October and early November reported to Lenovo. The computer manufacturer came last week, 17 days after the notification, with an update to the System Update tool. Then are the details of the vulnerabilities now publicly made, including a proof-of-concept that shows one of the attacks. Lenovo users are advised to install version 5.07.0019 or later of the System Update tool.

Monday, 23 November 2015

Fuss About Self-Signed Certificate On Dell Laptops


On the Internet fuss about a self-signed certificate which all Dell laptops would be delivered. On social news site Reddit reports reader Kevin Hicks how his new XPS Dell laptop a self-signed root certificate discovered called eDellRoot. Allows users could be attacked, for example via malware that uses the certificate.

The certificate on the Dell laptops is its own private key features that can not be exported. The key however, been found to be able to be copied. Dell user Joe Nord discovered on his laptop the same root certificate using the same private key.According to Nord Hicks and this is exactly the same situation as with Lenovo and Superfish debacle. The laptops from Lenovo came with adware that could intercept the encrypted traffic using a self-signed certificate to inject in here then ads.

In the case of Dell, however, the situation looks very different. The certificate can not be used namely to issue other certificates to perform eg man-in-the-middle attacks on HTTPS sites, says another reader on Reddit. Yet there is also criticism that Dell does not use a certificate from a valid certificate authority. Dell leaves in front of Hicks that eDellRoot is a trusted certificate and not a threat. Hicks's remark that the certificate or a security risk is the Dell Webcare team announced that the company will come with an explanation of the presence of the certificate. A spokesman confirmed to Security.NL Dell later today comes with an explanation.

Wednesday, 29 April 2015

Lenovo Provides Free Recovery Media Without Superfish


Owners of a Lenovo laptop can now apply for recovery media to install Windows and additional software without even the Super Fish-adware is installed together, so has let the computer manufacturer on the private forum know. Super Fish is a program that intercepted SSL connections to inject ads. The adware used for this purpose its own root certificate. Researchers managed to crack the password using the private key of the Superfish certificate.

This makes it possible in certain cases to Man-in-the-middle attacks against systems that perform Superfish and the certificate installed. In total Superfish appeared on more than 40 different types of laptops to be installed. Because of the Superfish debacle Lenovo announced several measures. For example, published a removal tool and put the manufacturer's promise that it will provide cleaner machines with less pre-installed software in the future. Also followed a free subscription of six months on the McAfee virus scanner.

Current owners of a laptop sit with the problem on their recovery media, such as a special recovery partition, Superfish is still present. If the computer is reinstalled using the recovery media is also Superfish replaced. Last month, Lenovo's own forum know that they worked to restore clean media without Superfish which can be requested via the support department. An employee of Lenovo claims that the recovery media will not be sent in bulk. "But if you need due to specific circumstances recovery media, please contact the service desk." Whether the media via CD or USB stick will be offered the employee does not know. We have asked for clarification about Lenovo.

Tuesday, 10 March 2015

Lenovo Provides Customers With Superfish-Adware 6 Months McAfee


Customers of computer manufacturer Lenovo laptop with the Superfish-adware can receive from next week try a virus McAfee for a period of six months without charge, as the company has let know .Because of the Superfish debacle Lenovo announced several measures. Was published as a removal tool and put the manufacturer's promise that it will provide cleaner machines with less pre-installed software in the future.

In addition, the customers a free subscription offer of a half years at McAfee Live Safe. The security software can be used on multiple devices and to protect systems against malware and other online threats. Duped consumers can already download the trial version of the software, to activate it, then next week on 16 March. In case users the security itself already bought their existing subscription will be extended by six months.

In total, more than 40 different types of laptops that Superfish standard was installed qualify for the program. Super Fish is a program that intercepted SSL connections to inject ads. The adware used for this purpose its own root certificate.Researchers managed to crack the password using the private key of the Superfish certificate. This makes it possible in some cases to Man-in-the-middle attacks against systems that perform Superfish and the certificate installed.

Lenovo Sold In February Even Laptop With Superfish-Adware


Although Lenovo has stopped installing Superfish consumers should still see if the offending adware is not on newly delivered systems. Discovered two readers of Ars Technica . On a laptop in early February by their neighbor was ordered discovered readers Superfish.

"Lenovo may say they Superfish installed no more since December, but the problem is that they still deliver systems that Superfish state," said Laura Buddine. Superfish intercepted SSL connections for injecting ads. A vulnerability in the adware meant that users could be attacked. The installed version of Windows on the investigated laptop dated for December.

According Buddine this shows that Lenovo's problem will not large enough to install the laptops in the warehouses again without Superfish. It also showed that the Super Fish-removal tool from Lenovo not removed all traces of adware. Thus were discovered after the delete several files of the adware and the certificate. Analysis of the source code of the removal tool that Lenovo posted on the Internet, it appears that there has recently released a new version that fixes several problems, including the removal of the Superfish files.

Friday, 6 March 2015

Oracle Adds "Adware" To Java Installation On Mac


For years, the installer for Java on Windows bundled with additional software, such as the Ask Toolbar, but now Oracle applies this practice also allows for the Java installer on Mac OS X. The Ask Toolbar is labeled by various parties as "adware." Under Windows Follower Ed Bott shows the Ask search engine bad results that are filled with advertisements that do not "organic" results can be distinguished in most cases.

In the case of Mac OS X is about 8 Java Update 40 whereby the Ask Toolbar is installed and the home page is changed. This version came out the week. The option to install the Ask Toolbar and change home is checked by default. Anyone who does not pay attention during installation has also a toolbar at. Bott discovered the new bundle of Oracle policy. He also discovered that the Ask developers in the Chrome Web Store does not use their own name, but "chromewebstore12".

Developers do when two other apps the same, allowing users might think that it is official Chrome apps. Oracle website now also makes mention that cooperation with certain parties that offer different products, but provides no further explanation or lets you know what people can do to remove Ask their system. Oracle's decision to join the toolbar follows the Lenovo Superfish debacle. Lenovo did this knowing that in the future cleaner machines will offer without much preinstalled software.

Monday, 2 March 2015

Mozilla Removes Superfish Certificate From Firefox

Mozilla Firefox

For Firefox users against Man-in-the-middle attacks to protect Mozilla has decided to remove the Superfish certificate from the browser, but only when users first have the controversial program their computers have been removed. Superfish installed on computers a root certificate that could intercept SSL traffic and then inject ads.

However, the adware found to contain a vulnerability whereby users could be attacked. Several parties, including Lenovo, came with removal tools to remove both Superfish Superfish if the installed certificate. Some of these tools do not remove remove the Superfish certificate from Firefox, allowing these users are still at risk of being attacked.

To ensure that these users are still safe Mozilla started rolling out a hotfix . This hotfix checks whether Superfish is removed and then remove the Superfish certificate from Firefox. If Superfish namely still on the computer and Mozilla would remove the certificate from Firefox, users would no longer be able to visit HTTPS sites. The browser developer advises users therefore to the removal instructions to follow Lenovo, which both the software and the certificate can be removed manually

Sunday, 1 March 2015

EFF: Install New Computer Ever Again

EFF

If you buy a new computer that must first install all over again, because the software that comes standard is not to be trusted. That secures the American civil rights movement EFF. Following are programs like Superfish and PrivDog who intercepted the SSL traffic of users to inject ads and thus users exposed themselves to all kinds of risks.

This week it was announced that next Superfish, standard on some Lenovo notebooks shipped, other programs intercepting SSL traffic. One of these programs was PrivDog . A vulnerability in certain versions of PrivDog caused the software each certificate which replaced the Internet came and intercepted by a self-signed certificate. Even though it was about certificates that were not valid in the first place.

The Decentralized SSL Observatory of the EFF, which gathers information from the HTTPS Everywhere plugin for Firefox, has collected more than 17,000 different certificates PrivDog users. "Each of these licenses may be an attack. Unfortunately there is no way to know this for sure" says Joseph Bonneau of the Electronic Frontier Foundation (EFF).

"So what have we learned from this Lenovo / Superfish / Komodia / PrivDog debacle? For users, we have learned that the software is pre-installed on your computer can not be trusted, which means that reinstalling a clean operating system standard now procedure must be if someone has bought a new computer, " said Bonneau. The main lesson, he says, for software companies, which must stop intercepting SSL traffic of their users.

Saturday, 28 February 2015

Lenovo Will Reduce Bloatware On Computers


Lenovo is the amount of preinstalled software on computers, also called " bloatware called "reduce significantly. That leaves the company said in a response to the Superfish debacle. "The events of last week, reinforce the principle that the customer experience, security and privacy should be our top priorities. With this in mind, we will pre-installed applications will be greatly reduced."

In a press release here said Lenovo will start right away. Will be at the launch of computers running Windows 10 "standard image" for computers only contain the operating system and related software as well as software needed to make the hardware work, security and Lenovo applications. "This would be what our industry" adware "and" bloatware "calls must eliminate." In some countries will install Lenovo programs that users expect in these areas.

Furthermore, the manufacturer information about all software preinstalled and explain what each application does. In addition, it will also collect feedback from users and experts going to make sure the right applications have been installed. In addition to changing the "preloadbeleid" will provide users with a Lenovo PC also receive a free six-month subscription to McAfee Safe Live service. About this action will soon appear more details.

Thursday, 26 February 2015

Domain Lenovo.com Hijacked Through DNS Adjustment


Attackers there yesterday managed to Lenovo.com hijack the DNS of the domain name to suit . Earlier this week, the attackers used the same technique in the Vietnamese Google website. In both cases Lizard Squad behind the DNS changes, as reported OpenDNS.

The Domain Name System (DNS) is similar to the directory and translates among other domain names into IP addresses. The DNS servers Lenovo.com and Google.com.vn change the attackers could then specify the IP addresses where the domain was pointing to. The IP address of the mail server could be modified so that emails for Lenovo.com found themselves at the attackers. In the case of Google.com.vn be the site for a Dutch IP address. Meanwhile, both websites are accessible again and the DNS changes undone.

On Twitter was the Malaysian Registrar WebNIC where both domain names are registered, then with the DNS adjustments in connection brought . IT journalist Brian Krebs reports that Webnic.cc via a command injection vulnerability has been hacked, leaving a rootkit could be uploaded. This rootkit would already have been removed. The website of WebNIC is still unreachable.

Wednesday, 25 February 2015

PrivDog: Only 57,000 Users At Risk


Adware PrivDog developer has released a security update after there was a vulnerability in the software detects allowing users targeted by Man-in-the-middle attack could be. In total, this "only" 57,000 users have run risk, says the developer. However, this is not the PrivDog software that comes with the programs of security provider and Certificate Authority Comodo. PrivDog makes adware that SSL connections are intercepted and software advertisements of "reliable partners" can inject.

Researchers discovered that PrivDog install a root certificate and thus intercepted each SSL certificate of websites using a self-signed certificate, even when it comes to SSL certificates that are not valid. As a result, the browser will accept HTTPS each certificate that is, whether by a Certificate Authority (CA) is signed or not. For example, users of public Wi-Fi networks could thus be the victim of a Man-in-the-middle attack. The vulnerability is present in versions 3.0.96.0 and 3.0.97.0 PrivDog.

These versions intercept SSL traffic and were downloaded from the website of PrivDog. Contrary to what was thought yesterday is Comodo Internet Security with an earlier version of PrivDog bundled working with a browser extension and thus is not directly vulnerable to this threat. That says researcher Hanno Boeck in addition to his research. PrivDog also confirms that the PrivDogplug-in that comes with the Comodo Browsers problem has not.

Globally, more than 57,000 people have downloaded the vulnerable PrivDog versions. According adware developer made ​​sure that the problem with some sites that use a self-signed certificate no certificate warning was given. However, the encryption was offered to the end user would remain intact, says PrivDog. Tonight there is rolled out an automatic update that fixes the problem by users.

Tuesday, 24 February 2015

Privdog Software Worse Than Superfish Adware


After computer manufacturer Lenovo appears to combine security provider Comodo adware with its own software SSL traffic intercepted, only the impact is much greater than with Lenovo's Superfish was. That says researcher Hanno Bock . Comodo is known software like Comodo Internet Security and Comodo Dragon Browser. With some of the programs PrivDog-adware is included.

Like Superfish intercepted PrivDog HTTPS traffic to inject ads from "reliable partners". Late last year, the ability to filter HTTPS traffic was already on the forum Comodo discussed . The software is after Superfish scandal now in the spotlight. A user decided because Superfish a test page to do, which warns users if their HTTPS connection is manipulated. Although the user is not used Superfish he got a warning. Then this user reported on Hacker News that the possible was the PrivDog-adware.

PrivDog not have the same vulnerability as Superfish, using a weak certificate and a weak password to protect the private key of the certificate, but one which is many times as possible according to Bock. Although Superfish same certificate and key used for all installations, PrivDog makes for each installation a separate key and certificate. The biggest problem is that each certificate PrivDog intercepted and replaced by a self-signed certificate.

It is also about certificates that were not valid in the first place. As a result, the browser will accept HTTPS each certificate that is, whether by a Certificate Authority (CA) is signed or not. "We are still trying to find out the details, but it looks bad," Bock says. The researcher also finds it strange that Comodo, which is itself a CA bundle adware with their own software. "If the CA would be their job to protect HTTPS, not break," the researcher concludes.

Meanwhile warns also the CERT Coordination Center (CERT / CC) at Carnegie Mellon University for PrivDog. An attacker could according to the CERT / CC HTTPS sites spoof and intercept HTTPS traffic without users see a certificate warning.Users will also be advised to remove PrivDog. This would also be the root certificate in question to be removed.

US-CERT writes: "Adtrustmedia PrivDog is promoted by the Comodo Group, which is an organization that offers SSL certificates and authentication solutions." A variant of PrivDog that is not affected by this issue is shipped with products produced by Comodo (see below). This makes this case especially interesting because Comodo itself is a certificate authority (they had issues before). As ACLU technologist Christopher Soghoian points out on Twitter the founder of PrivDog is the CEO of Comodo. (See this blog post.)

Update/Clarification: The dangerous TLS interception behaviour is part of the latest version of PrivDog 3.0.96.0, which can be downloaded from the PrivDog webpage. Comodo Internet Security bundles an earlier version of PrivDog that works with a browser extension, so it is not directly vulnerable to this threat. According to online sources PrivDog 3.0.96.0 was released in December 2014 and changed the TLS interception technology.

Update 2: Privdog published an Advisory.