Superfish doubles down, says HTTPS-busting adware poses no security risk
Denial comes despite near-unanimous agreement that it left Lenovo users wide open. — Following security professionals' near-unanimous condemnation of adware that hijacked encrypted Web connections on Lenovo computers …
Context & Ripple Effects
The Superfish story has moved fast since researchers found man-in-the-middle adware pre-installed on Lenovo notebooks breaking HTTPS in Chrome and Internet Explorer. Lenovo had already quietly disabled the software in January but claimed no substantiated security concerns, per its own account in Lenovo's January disabling of Superfish.
Superfish's denial lands at the moment the rest of the industry treats the flaw as settled: Microsoft pushed a Windows Defender update to strip the software from affected machines (Microsoft's Windows Defender removal update), and the US Department of Homeland Security issued an advisory citing SSL spoofing risk (DHS warning to Lenovo customers). The company is now arguing against its own customers' security tooling and a national security agency.
First-order effects
- Superfish's no-risk position puts it directly against Microsoft, which is actively deleting the software via Windows Defender, and against DHS, which is telling Lenovo owners to remove it — the vendor's claim is contradicted by two of the most credible actors in the story.
Second-order effects
- Lenovo inherits the reputational damage regardless of what Superfish says: the CTO Peter Hortensius apology and promised security-policy overhaul (Hortensius's apology and new security policy) show the OEM conceding within days what its software partner still denies.
Third-order effects
- If OS vendors and regulators keep treating pre-installed adware as malware to be auto-removed, the OEM bundling channel loses its viability — laptop makers face a structural choice between ad revenue partnerships and shipping machines that their own platforms flag as compromised.
The trend: Pre-installed OEM software is being reclassified from bundled convenience to supply-chain attack surface, with OS vendors and government agencies now policing what ships on consumer laptops.