Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Superfish CEO says it is "transparent in what our software does"

by The Gurus
February 20, 2015
in Editor's News
Share on FacebookShare on Twitter

Software provider Superfish has said it stands by claims made by Lenovo, that there is nothing malicious about its product.
 
In a statement to sent IT Security Guru, Superfish CEO Adi Pinhas said that the company is standing by the comments made by Lenovo, and confirmed that Superfish has not been active on Lenovo laptops since December.
 
He said: “It is important to note [that] Superfish is completely transparent in what our software does and at no time were consumers vulnerable – we stand by this today. Lenovo will be releasing a statement later today with all of the specifics that clarify that there has been no wrong doing on our end.”
 
The statement from Lenovo claimed that it pre-installed the third-party software Superfish “in our effort to enhance our user experience” and said it is working directly with Superfish and with other industry partners to ensure we address any possible security issues now and in the future.
 
“Superfish technology is purely based on contextual/image and not behavioural,” Lenovo said. “It does not profile nor monitor user behaviour. It does not record user information. It does not know who the user is. Users are not tracked nor re-targeted. Every session is independent. Users are given a choice whether or not to use the product.”
 
However this is still being contested by industry researchers. Marc Rogers, security researcher at Cloudflare, said on Twitter that “it blows my mind that Lenovo are trying to pass the threat from these certificates off as ‘theoretical’ or otherwise diminish the risk”, while blogger Robert Graham said “Lenovo’s statement is a bald face lie. If this program were so great, users would be able to download it themselves”.
 
Adam Winn, manager at OPSWAT, said that it was “shocking” that Lenovo would preinstall software that breaks the SSL trust chain in such a fundamental way, and that with a dedicated following of IT professionals, as evidenced by the ubiquity of Thinkpads in enterprise, there’s no doubt that this incident will come with a heavy hit to Lenovo’s bottom line. He said: “No IT administrator will tolerate a MITM attack on company owned or even BYOD assets.”
 
TK Keanini, CTO of Lancope, said: “I’m happy to see consumers pushing back and demanding greater security out of the box. Unless the market steps up and ask for more secure systems, vendors will keep doing silly and sometimes irresponsible things.
 
“I remember purchasing a laptop for my daughter a few years back and the retailer wanted me to pay extra to remove all the adware and ‘extra’s from the unit. This is not right.  Pay extra so that I can get rid of all the advertising software and programs that slow my experience down?  It is like buying a car and paying extra to remove the ads painted on the

Tags: CertificateHTTPSSSLSuperfish
ShareTweet
Previous Post

Intelligence agencies targeted Gemalto to access SIM data and calls

Next Post

Let's add mutability to the things we cannot change

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol