You should be warned that it ships with crapware (as many do to increase OEM profits)…but it also ships with Superfish on it.
Superfish is adware which ‘sees’ the images on the webpages you visit and then offers ads compatible with them…for instance, if you look for a new table, it will try to insert ads with tables in them to “help” you. SO you say, All the sights I look at are https protected. Sad news: Superfish also installs a root certificate in your Windows certificate store, which cancels the https protection. Perfect!
“The pre-installed certificate is the exact same on all systems as it seems. And so is obviously the private key, which seems to be part of the Superfish software as well. What it means? Well, you can just issue certificates and computers having the Superfish software installed will recognize them as valid.” – infected.io
*poof: Security severely compromised: Every site you visit (banking included) is man-in-the-middled.
OK…I’ll just uninstall Superfish, you say. You’ll also have to uninstall the certificate…and you have to do that yourself.
Here’s how:
First locate the Windows certificate store (Screen shot from gHacks):
- Tap on the Windows-key to bring up the start menu or start screen.
- Type certmgr.msc and hit enter. This opens the Certificate Manager.
- Use the folder structure on the left to navigate to Trusted Root Certification Authorities -> Certificates.
- Check if Superfish Inc. is listed among the certificates.
- If it is, right-click the certificate and select Delete from the context menu to remove it.
I have to agree with Martin Brinkmann. It’s bad enough having to work at removing all the crapware they put on your computer, which you didn’t ask for, have any use for, nor want.
Now? Lenovo actually installed adware which spies on you and a root certificate which makes your shiny new computer vulnerable to man-in-the-middle attacks (of which there are many and usually done via phishing).
This is a REALLY poor business practice which I hope they didn’t know about (the root certificate part)…and it could damage their rep for many years to come. Frankly, it’s a scandal.
Sources:
http://www.ghacks.net/2015/02/19/lenovo-pcs-ship-with-preinstalled-adware-and-root-certificate/?_m=3n%2e0038%2e1524%2ehj0ao01hy5%2e1kul
Others in the text. All checked. All safe.