Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I use Linux, but Lenovo's reputation is still burned in my eyes ever since the Superfish incident. I'm very happy we have other names in the Linux laptop game.

(Context: Lenovo installed universal root CAs on their laptops during the 2010s, so they could serve ads. They were tied to firmware IIRC, so, reinstalling Windows would not remove the malware.)



I understand why you have a problem with Lenovo following the incident, but ThinkPads are something else, and they weren't impacted by Superfish.

Non-ThinkPad Lenovos are not great by any mean. They are unremarkable consumer-grade laptops. ThinkPads are a legacy from IBM that Lenovo is smart enough to keep separate from the rest.


Still not acceptable. It would be hard for me to buy a ThinkPad (I have bought many in the past).

Obviously Lenovo has zero integrity and will spy on us or cheat us in some other way if they think they can do it without getting caught.

Sad that nobody else makes laptops with the little nub for pointing the mouse.


I used a TP from the 2013, 2014 era, and I have my current main laptop as a TP from 2017...

The old TP was fantastic. Really out of date hardware, but it did the job. New one is great, in theory (spec-wise), but its a much cheaper build, breaks more, and just generally has far more issues than I remember with the old one. I think I had one in the middle too which was just straight up an awful peice of junk...

When Lenovo got bought out by China, they weren't really that smart - they tried to consumerize their TP and thereby cut costs - the features they brought back to modern TPs are still nice but you just don't get the same attention to detail anymore...IMHO.


> but Lenovo's reputation is still burned in my eyes ever since the Superfish incident.

I guess you don't use any other company either because every other company has committed something bad in the past? (Sony had rootkits in their CDs, Microsoft has been anticompetitive by forcing the hands of OEMs and inserting spyware in their OS, the list can go on...).

What matters is how each company answers to their mistakes. If they double-down, you are right to avoid them. If they recognize them and make amends, it's OK to give them a chance again.


How far does that list go? I indeed don't use Sony software and I avoid Microsoft's. I don't know many other violations of this severity. For example, Dell had pre-installed root CAs (but weren't persistent like Lenovo's), and many other laptop manufacturers haven't preinstalled root CAs (e.g. HP hasn't afaik).

With Framework and System76 and other smaller manufacturers making Linux-first laptops, I'm especially disinclined to ever consider Lenovo again.


That was over 10 years ago, a mistake which the company has shown no signs of repeating.


They might have started it over 10 years ago, but they kept the Superfish malware until 2015, when they offered removal tools.

(For context in the future, this comment was made in 2022, when the Superfish Lenovo security controversy was only 7 years old.)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: