Lenovo disabled Superfish in January, but the company says it has not found “evidence to substantiate security concerns”
Nate Anderson / Ars Technica :
Context & Ripple Effects
Lenovo is in full damage control over Superfish, the HTTPS-intercepting adware it shipped on consumer PCs: the company disabled it in January and now argues there is no "evidence to substantiate security concerns." The problem for that line is that the rest of the industry isn't waiting on Lenovo's assessment — Microsoft has already updated Windows Defender to strip Superfish from infected machines, treating the software as malware regardless of what Lenovo says.
Superfish itself is doubling down with the same no-risk claim as its OEM partner, which puts the two companies' public posture directly at odds with antivirus vendors' actions. Lenovo's next moves — a dedicated automatic removal tool and a formal apology from CTO Peter Hortensius promising a new security policy — show how quickly the "no evidence" position collapsed under pressure.
First-order effects
- Owners of Lenovo PCs with pre-installed Superfish are left with conflicting guidance: their PC maker says the risk is unsubstantiated, while Microsoft's own antivirus flags and removes the same software.
Second-order effects
- Microsoft's unilateral Defender remediation forces Lenovo's hand — the company ships its own removal tool within days rather than defend the software, and CTO Peter Hortensius issues an apology committing Lenovo to a new pre-installation security policy.
Third-order effects
- If OEM-bundled adware keeps getting treated as malware by platform vendors regardless of the manufacturer's stance, the economics of shipping third-party preloads weaken: the reputational cost lands on the hardware brand even when the vendor wrote the code.
The trend: PC makers are losing control of the security narrative around pre-installed software, as OS-level antivirus now overrides OEM claims about bundled adware.