Conn. AG launches Lenovo-Superfish ‘crapware’ probe
Gregg Keizer / Computerworld :
Context & Ripple Effects
The Connecticut AG probe turns a two-week technical fire drill into a legal problem. Lenovo had already disabled Superfish in January while denying evidence of security concerns, then faced a cascade: a DHS advisory urging customers to remove the software over SSL-spoofing risk, a Windows Defender update that stripped it automatically, and Lenovo shipping its own removal tool — all before the company promised to stop bundling crapware.
What makes the AG inquiry matter is timing and posture: it arrives days after Lenovo's cleanup commitments, meaning regulators are now auditing conduct the company itself framed as routine pre-installation practice rather than a security lapse.
First-order effects
- Lenovo faces document demands and potential enforcement action in Connecticut on top of the reputational damage, with its January claim that it found no 'evidence to substantiate security concerns' now subject to official scrutiny against DHS's contrary SSL-spoofing warning.
Second-order effects
- Other PC makers that bundle adware face pressure to audit their own pre-install deals before state AGs widen the net, and software vendors like Superfish lose the OEM distribution channel Lenovo just abandoned.
Third-order effects
- If state-level probes follow the DHS-validated security framing, OEM crapware bundling shifts from a tolerated revenue line to a legal liability, pushing PC makers toward cleaner images as a compliance position rather than a marketing one.
The trend: Preinstalled OEM software is moving from quiet monetization to regulated territory, with security agencies' findings becoming the trigger for state attorney general action.