View Single Post
Old 09-06-2017, 07:57 AM  
blackmonsters
Making PHP work
 
blackmonsters's Avatar
 
Industry Role:
Join Date: Nov 2002
Location: 🌎🌅🌈🌇
Posts: 20,227
Lenovo will pay a $3.5 million fine for preinstalling adware on certain laptops

They also spoofed security certificates for https sites the surfer went to!


https://www.ftc.gov/news-events/pres...s-preinstalled

Lenovo Inc., one of the world?s largest computer manufacturers, has agreed to settle charges by the Federal Trade Commission and 32 State Attorneys General that the company harmed consumers by pre-loading software on some laptops that compromised security protections in order to deliver ads to consumers.

In its complaint, the FTC charged that beginning in August 2014 Lenovo began selling consumer laptops in the United States that came with a preinstalled ?man-in-the-middle? software program called VisualDiscovery that interfered with how a user?s browser interacted with websites and created serious security vulnerabilities.

?Lenovo compromised consumers? privacy when it preloaded software that could access consumers? sensitive information without adequate notice or consent to its use,? said Acting FTC Chairman Maureen K. Ohlhausen. ?This conduct is even more serious because the software compromised online security protections that consumers rely on.?

VisualDiscovery software, developed by a company called Superfish, Inc., was installed on hundreds of thousands of Lenovo laptops. It delivered pop-up ads from the company?s retail partners whenever a user?s cursor hovered over a similar looking product on a website.

To deliver its ads, VisualDiscovery acted as a ?man-in-the-middle? between consumers? browsers and the websites they visited, even those websites that were encrypted. Without the consumer?s knowledge or consent, this ?man-in-the-middle? technique allowed VisualDiscovery to access all of a consumer?s sensitive personal information transmitted over the Internet, including login credentials, Social Security numbers, medical information, and financial and payment information. While VisualDiscovery collected and transmitted to Superfish?s servers more limited information, such as the websites the user browsed and the consumer?s IP address, Superfish had the ability to collect more information.

To facilitate its display of pop-up ads on encrypted websites (those that include https:// in the web address), the complaint also alleges that VisualDiscovery used an insecure method to replace digital certificates for those websites with its own VisualDiscovery-signed certificates. Digital certificates are used to signal to a user?s browser that the encrypted websites visited by a consumer are authentic and not imposters. VisualDiscovery, however, did not adequately verify that the websites? digital certificates were valid before replacing them, and used the same, easy-to-crack password on all affected laptops rather than using unique passwords for each laptop.
__________________
Make Money with Porn
blackmonsters is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote