large image

Trusted Reviews is supported by its audience. If you purchase through links on our site, we may earn a commission. Learn more.

Lenovo laptops could put bank info at risk, security experts warn

Lenovo has potentially put thousands of users at risk by installing adware that can be easily exploited on a number of its laptops, latest reports have suggested.

Security experts (via The Verge) have revealed that enterprising hackers could steal sensitive information like passwords and bank details by exploiting the software.

The adware is called Superfish, a program that analyses images you look at during browsing sessions.

It then compares those images with upwards of 70,000 online stores to find lower priced products to push back to you in the form of advertisements.

The issue lies with how Superfish operates on your computer, and how hackers can take advantage of this.

When secure websites like banks want to prove your connection is legitimate, it will request an SSL certificate. Usually these come from trusted authorities that verify your connection.

Superfish circumvents this by producing its own SSL certificates to view content on otherwise secure websites, all in the hope of raking in advertising cash.

Related: Best Laptops 2015

What’s more, Superfish uses the same key for its root certificates across all machines. If hackers can crack this key, they could create their own certificates on third-party machines through the Superfish software.

This means that hackers could convince your bank’s website that their connection was legitimate, and potentially nab sensitive information.

Hackers could even write new software for Lenovo machines using the key, offering more sophisticated entry to private data.

Lenovo provided TrustedReviews with the following statement:

“Lenovo removed Superfish from the preloads of new consumer systems in January 2015. At the same time Superfish disabled existing Lenovo machines in market from activating Superfish. Superfish was preloaded onto a select number of consumer models only. Lenovo is thoroughly investigating all and any new concerns raised regarding Superfish.”

A second statement contained the following excerpt:

“We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns.  But we know that users reacted to this issue with concern, and so we have taken direct action to stop shipping any products with this software.”

Why trust our journalism?

Founded in 2004, Trusted Reviews exists to give our readers thorough, unbiased and independent advice on what to buy.

Today, we have 9 million users a month around the world, and assess more than 1,000 products a year.

author icon

Editorial independence

Editorial independence means being able to give an unbiased verdict about a product or company, with the avoidance of conflicts of interest. To ensure this is possible, every member of the editorial staff follows a clear code of conduct.

author icon

Professional conduct

We also expect our journalists to follow clear ethical standards in their work. Our staff members must strive for honesty and accuracy in everything they do. We follow the IPSO Editors’ code of practice to underpin these standards.