These big-name laptops are infested with security bugs – study

frogboy

In memoriam 1961-2018
Thread author
Verified
Top Poster
Well-known
Jun 9, 2013
6,720
Bloatware creates easy pwnage
laptop_user_photo_via_shutterstock.jpg


Computers from many of the biggest PC makers are riddled with easy-to-exploit vulnerabilities in pre-loaded software, security researchers warn.

The research from Duo Security shows that bloatware is not just a nuisance that causes a lag in system boot-up, but a security risk. Laptops from Acer, Asus, Dell, HP and Lenovo all have at least one security vulnerability that can lead to a full system compromise. Most of the vulnerabilities would be straightforward to exploit even for technically unsophisticated hackers, according to Duo Security.

Lenovo copped an enormous amount of flack after it began bundling Superfish adware with some of its computers in September 2014. Superfish adware was installed on some Lenovo PCs with a trusted root certification authority (CA) certificate, allowing an attacker to spoof HTTPS traffic.

A machine with Superfish VisualDiscovery installed will be vulnerable to SSL spoofing attacks without a warning from the browser, as US CERT warned around the time the scandal broke in early 2015.

Duo's research shows the Superfish controversy was but an extreme example of a wider security problem involving pre-installed software from multiple manufacturers.

"The OEM software landscape is complicated and includes a depressing amount of superfluous tools for vendor support, free software trials, and other vendor-incentivized crapware," Duo Security researchers warn.

"Some apps do nothing more than add a shortcut to launch your web browser to a specific site.

Full Article. These big-name laptops are infested with security bugs – study
 

rigor

Level 2
Verified
May 20, 2016
71
True. What lenovo did is mindblowing. Bloatware is mostly for cheaper laptops though, for example, superfish was only on <$1000 laptops. Thinkpads didn't have it, correct me if im wrong. Every time I buy a laptop I always do a clean install to get rid of all the crap.
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
You know OEM's are just an instrument to boost the sales because they can insert a lot of 'garbage'. So commission will be share not only on the manufacturer but also to the partnership.

But still some brands provide mild yet safe OEM without issue.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top