Superfish points fingers over ad software security flaws

February 22, 2015 byBrandon Bailey
In this Aug. 15, 2013 file photo, people walk past a Lenovo flagship experience store in Beijing, China. Security researchers revealed Thursday, Feb. 19, 2015, that some computers sold by China's Lenovo, the world's biggest PC maker, had a major security hole that would let any garden-variety hacker impersonate shopping, banking and other websites and steal users' credit card numbers and other personal data. (AP Photo/Andy Wong, File)

A little-known Silicon Valley startup was caught in a firestorm of criticism this week for making software that exposed Lenovo laptop users to hackers bent on stealing personal information. But Superfish Inc. has also won praise for producing visual search technology that many see as the next big thing in online shopping.

Is Superfish an Internet pioneer or a computer-user's privacy nightmare?

Either way, don't expect a mea culpa. Faced with a withering publicity barrage that could jeopardize any startup's future, Superfish CEO Adi Pinhas blamed another company for the security flaw and complained about what he called "false and misleading statements made by some media commentators and bloggers."

Researchers revealed Thursday that some laptops sold by China's Lenovo, the world's biggest PC maker, had a security flaw that could let hackers impersonate shopping, banking and other websites and steal users' and other personal data.

Lenovo has since apologized for pre-loading the computers with Superfish's visual search software, which captures images that users view online, such as a sofa or pair of shoes, and then shows them ads for similar products. By itself, the image recognition algorithm might not be a security risk. But the problem arose because Superfish used software from another company that can eavesdrop when Internet users visit secure or encrypted websites.

That software replaced the encryption code on websites with its own easily-hacked code, according to several researchers. The Department of Homeland Security issued an alert Friday saying Lenovo customers should remove Superfish software because of the hacking dangers

Superfish on Friday insisted its own code is safe and said the was "introduced unintentionally by a third party." In an email to The Associated Press, Pinhas identified that party as Komodia, a tech startup based in Israel that makes software for other companies, including tools for companies that show online ads and for programs parents can use to monitor their children's Web surfing.

Some experts say the problem may extend beyond Lenovo. The Komodia tool could imperil any company or program using the same code. "It's not just Superfish, other companies may be vulnerable," said Robert Graham, CEO of Errata Security. Komodia CEO Barak Weichselbaum declined comment Friday.

Launched in Israel by Pinhas and fellow entrepreneur Michael Chertok, Superfish is among a handful of companies pioneering the use of "visual recognition" technology, which industry experts say could revolutionize by letting people search online with pictures as easily as they now search with words. Superfish's visual recognition algorithms can analyze a picture and search through a database for similar images, even if they're not labeled with descriptive text.

"I've been impressed. They're probably one of the best technologies that's out there," said Sucharita Mulpuru, a Forrester Research analyst. "It can be a powerful tool for a lot of things, but definitely for shopping and e-commerce."

Consumers will see more of this in the future, said Yory Wurmser at the eMarketer research firm. Inc. built a similar shopping feature into its Fire smartphone last year. Google Inc., Facebook Inc., Pinterest and other tech giants are investing heavily in .

Now based in Palo Alto, Calif., Pinhas has called Superfish a "deep technology company." But Superfish critics call its products "ad-ware" or worse. Several Internet message boards are filled with complaints that an earlier Superfish program, WindowShopper, bombarded users with annoying ads and diverted them to websites they didn't want to visit. Pinhas didn't respond to an emailed question about WindowShopper.

Superfish, which was founded in 2006, said last year that it had 85 employees and about $45 million in annual revenue. As a privately held startup, the company doesn't disclose major customers or contracts. But with the Lenovo debacle, Superfish's brand is taking a hit. However the flaw was introduced, critics say Superfish and Lenovo should have caught the problem sooner.

"They probably saw this as a way to generate revenue, but the security implications are pretty severe," said analyst Ken Westin of the cybersecurity firm Tripwire.

Lenovo released a software tool Friday to help customers remove the Superfish code from their laptops. It can be found at … /superfish_uninstall . But some experts say users may want to wipe their hard drives and start over, re-installing the Windows operating system however.

That's not an easy task for casual users, said Westin, "but it's the best way to be completely sure."

Explore further: Lenovo stops Superfish preloads and issues advisory

Related Stories

Lenovo stops Superfish preloads and issues advisory

February 21, 2015

Lenovo has seen calmer weeks. News sites in droves rang chimes and sirens over an adware program on some Lenovo models escalating to concerns about the potential risk of a Man in the Middle threat. Lenovo has been attempting ...

Visual search to shop: gimmick or game changing?

August 28, 2014

Imagine using your phone to snap a photo of the cool pair of sunglasses your friend is wearing and instantly receiving a slew of information about the shades along with a link to order them.

US clears $2.3 bln Lenovo deal for IBM unit

August 15, 2014

IBM said Friday that US authorities had cleared a $2.3 billion deal allowing China-based Lenovo to take over its server unit after a national security review.

Recommended for you

Technology near for real-time TV political fact checks

January 18, 2019

A Duke University team expects to have a product available for election year that will allow television networks to offer real-time fact checks onscreen when a politician makes a questionable claim during a speech or debate.

Privacy becomes a selling point at tech show

January 7, 2019

Apple is not among the exhibitors at the 2019 Consumer Electronics Show, but that didn't prevent the iPhone maker from sending a message to attendees on a large billboard.

China's Huawei unveils chip for global big data market

January 7, 2019

Huawei Technologies Ltd. showed off a new processor chip for data centers and cloud computing Monday, expanding into new and growing markets despite Western warnings the company might be a security risk.

1 comment

Adjust slider to filter visible comments by rank

Display comments: newest first

5 / 5 (1) Feb 22, 2015
Software that monitors and reports users activity can be considering spyware and it is clear invasion of privacy, with little practical difference to the malware used by hackers. Including other software with the intent of monitoring connections that are supposed to be secure just makes it worse and blaming that third party does not change their intent. Adware generally does have some aspect of spyware and tends to interfere with the system to display ads which can cause problems for users.

Their software appears to meet the definition of malware and it is definitely something that I was never want bundled on my new computer. Lenovo knowingly bundled their software and have breached their customers trust in doing so.

Please sign in to add a comment. Registration is free, and takes less than a minute. Read more

Click here to reset your password.
Sign in to get notified via email when new comments are made.