Lenovo's Response to Its Dangerous Adware Is Astonishingly Clueless
If you've bought a Lenovo laptop anytime since August, it may have shipped with a dangerous bit of adware known as Visual Discovery by Superfish. It's the kind of software add-on that computer makers are often paid to include with their hardware.
Context & Ripple Effects
Since at least August 2014, Lenovo has been shipping consumer notebooks with Superfish's Visual Discovery adware preinstalled — software the company was reportedly paid to include — and the man-in-the-middle technique it uses breaks HTTPS connections in Chrome and Internet Explorer, exposing buyers on shared networks. Within days of the disclosure, Microsoft updated Windows Defender to strip the software from customer machines itself, while Lenovo scrambled out its own automatic removal tool.
The response arc is what drew Wired's 'clueless' framing: rather than owning the failure, Superfish publicly insisted its HTTPS-busting adware poses no security risk, leaving Lenovo defending a partner whose posture made the apology look worse. The episode also wasn't a one-off — roughly a year later Lenovo asked users to uninstall its Accelerator app after Duo Labs flagged another insecure preinstall vulnerable to MITM attacks.
First-order effects
- Affected buyers face immediate exposure: the adware intercepts encrypted traffic in mainstream browsers, so any Lenovo laptop bought since August carries a working HTTPS downgrade until Defender or Lenovo's tool cleans it.
- Microsoft is now modifying machines sold by an OEM partner — Windows Defender removing Superfish overrides Lenovo's factory image and sets a precedent for the OS vendor policing preinstalled software directly.
Second-order effects
- The paid-bloatware revenue stream comes under scrutiny: if shipping adware costs more in trust than it earns per unit, every PC maker weighing preinstall deals must reprice that income against brand and security risk.
- Superfish's public denial forces Lenovo to choose between distancing itself from the vendor or absorbing the reputational damage jointly — a split that weakens both players' standing with enterprise and security-conscious buyers.
Third-order effects
- If the pattern holds — Superfish in 2015, the Accelerator app in 2016 — OEM preinstalled-software economics become structurally untenable, pushing PC makers away from adware complements and back toward competing on hardware margin alone, a reversal of the classic margin-migration-to-complements playbook.
- Security researchers and OS vendors, not OEMs, emerge as the de facto gatekeepers of what ships on consumer PCs — a governance shift regulators could formalize if vendor self-policing keeps failing.
The trend: PC makers' adware-funded bloatware model is colliding with security research and OS-vendor enforcement that now strips preinstalled software remotely, making the complement-revenue trade increasingly unprofitable.