TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Lenovo: researchers find 'massive security risk'

104 pointsby tpatkeabout 10 years ago

10 comments

orthecreedenceabout 10 years ago
It seems from the article that the best way to handle this is to uninstall all the trash that comes with a new computer (or hell, reinstall windows from scratch). Do I need Lenovo's power management tools? No. Do I need its Wifi connection manager? No. Windows has all this stuff already and it works really, really well.
评论 #9500833 未加载
评论 #9499696 未加载
评论 #9500932 未加载
评论 #9500090 未加载
评论 #9499533 未加载
评论 #9499632 未加载
评论 #9499511 未加载
评论 #9500428 未加载
评论 #9500741 未加载
themeekabout 10 years ago
Lenovo has, for years, been banned from US government use. They even have a patent on recovering TPM keys (<a href="http:&#x2F;&#x2F;www.google.com&#x2F;patents&#x2F;US8908867" rel="nofollow">http:&#x2F;&#x2F;www.google.com&#x2F;patents&#x2F;US8908867</a>).<p>It is well known (via Snowden) that the US installs backdoors into US hardware and software for export to China, and it has for at least 15 years warned about the same from imports.<p>So none of this is particularly new. What is new is that the US is now moving against China on all fronts to prevent it from acquiring superpower status - to isolate it economically and politically, to block its trade and international investment programs, and to increase the risk of its using its military (with the second largest funding of any nation) to project power lawfully in the Asia Pacific.<p>So these articles come at a good time for the US.<p>You should not trust pretty much any hardware - recent revelations have shown that products come with backdoors; that is the article does not establish the absence of &#x27;security flaws&#x27; by other manufacturers.
评论 #9500267 未加载
nemoniacabout 10 years ago
I&#x27;ve had a bunch of Lenovo Thinkpads. Each time, the first thing I do is wipe it and install Linux.
评论 #9499595 未加载
SixSigmaabout 10 years ago
&gt; The other two flaws would allow attackers to gain a greater level of control over a system than they should have.<p>What level of control should an attacker have ?
评论 #9499334 未加载
评论 #9499349 未加载
DanBlakeabout 10 years ago
Kind of crappy title, and mostly old news.<p>Should be : Researchers: Lenovo computers contain &#x27;massive security risk&#x27;
lifeisstillgoodabout 10 years ago
So I feel like I missed a memo. Is there a list &#x2F; primer on what we do and do not know about hardware backdoors, firmware backdoors and software backdoors?<p>This bothers me - a16z podcast also threw up a reference to &quot;200 security hygiene&quot; functions - keeping patches up to date and encryption at rest. But Incan only get to about ten.<p>Is there an appendix in SysAdmin &#x2F; oReilly I should read or do I have to watch all the CEF notifications and work backwards to what preventative action Inshould stick in my sh file.<p>It&#x27;s a serious question - I just don&#x27;t feel I know what is dangerous out there anymore let alone have it automated.
badloginagainabout 10 years ago
I have a Lenovo ThinkPad, if I blow away the stock version of Windows 8 I&#x27;m currently running with an incoming Windows 10, will that blow away all the Lenovo bloatware?
评论 #9500648 未加载
评论 #9499966 未加载
评论 #9500157 未加载
smarterchildabout 10 years ago
<a href="https:&#x2F;&#x2F;support.lenovo.com&#x2F;us&#x2F;en&#x2F;product_security&#x2F;lsu_privilege" rel="nofollow">https:&#x2F;&#x2F;support.lenovo.com&#x2F;us&#x2F;en&#x2F;product_security&#x2F;lsu_privil...</a><p>If this is considered &quot;Medium&quot; Severity, how bad would it have to be to become High?
评论 #9500164 未加载
评论 #9500045 未加载
jefuriiabout 10 years ago
Yet another reason to wipe the drive on a new computer and just install Linux...
评论 #9501623 未加载
ryanlolabout 10 years ago
I really don&#x27;t think a privesc vulnerability on Windows can be considered a &quot;massive security risk&quot; at this point.