Your membership has expired

The payment for your account couldn't be processed or you've canceled your account with us.

Re-activate

Save products you love, products you own and much more!

Save products icon

Other Membership Benefits:

Savings icon Exclusive Deals for Members Best time to buy icon Best Time to Buy Products Recall tracker icon Recall & Safety Alerts TV screen optimizer icon TV Screen Optimizer and more

    How Lenovo's dangerous Superfish adware put its customers at risk

    If you have a new Lenovo laptop, here's what you need to do

    Published: February 20, 2015 01:20 PM
    Lenovo Miix 2 11

    The Internet is lighting up with warnings about Superfish, an adware program that came preinstalled on many Lenovo laptops in the past six months. Like a lot of the bloatware that comes on new computers, Superfish exists to help push advertising, not to serve any real consumer need. That would be annoying enough, but Superfish seriously undermines the user's safety, according to many security experts.  

    Superfish is a piece of third-party software that Lenovo installed to, as it says in its apology to consumers, "enhance the shopping experience." That means it's meant to help advertisers target potential customers. But security experts say the software makes it easy for cybercriminals to intercept your data as it travels from your computer out to the Internet.

    That's because of the way Superfish deals with what's called a root certificate. These certificates tell your computer what content to trust when you go to a secure site. The problem is, in order to place ads, Superfish installs its own root certificate that allows it to intercept and unencrypt your encrypted communications. Even if Lenovo's paying customers don't mind Superfish intruding in that way, they should be concerned because the software opens their communications to a malicious man-in-the-middle attack by hackers.

    "What they would get is everything passing out of your machine—every password, every bank-account number, every e-mail," said Professor Fred Cate, founding director and senior fellow at the Center for Applied Cybersecurity Research at Indiana University's Maurer School of Law. "It's pretty dire, but we don't know yet if anyone has exploited it."

    Find out which free security software provides the best protection from malware. And check our computer buying guide and Ratings

    The affected computers were laptops shipped between September 2014 and February 2015. Check out the complete list, which includes dozens of models.

    If you own one of these laptops, uninstall Superfish and its certificate immediately. Microsoft confirms that its Windows Defender security software removes both. If you don't already have it, you can download Windows Defender.

    You also can remove Superfish manually using these instructions, which are basically just a typical software uninstall. You must also remove the certificate manually, by searching for and deleting it. Instructions for doing that are on the same page.

    What's really needed is a one-button solution to get rid of Superfish and its certificate, said Cate. Without that, he added, "it will be weeks before people get it off."

    Let's hope that Lenovo and Superfish are working overtime to get that one-step fix out to consumers.

    —Donna Tapellini

    Find Ratings

    Computers Ratings

    View and compare all Computers ratings.

    Antivirus Software Ratings

    View and compare all Antivirus Software ratings.

    E-mail Newsletters

    FREE e-mail Newsletters! Choose from cars, safety, health, and more!
    Already signed-up?
    Manage your newsletters here too.

    Electronics News

    Cars

    Cars Build & Buy Car Buying Service
    Save thousands off MSRP with upfront dealer pricing information and a transparent car buying experience.

    See your savings

    Mobile

    Mobile Get Ratings on the go and compare
    while you shop

    Learn more