Lenovo to cough up US$3.5M over Superfish episode
The company has also agreed to make changes to how it sells its laptops
The company has also agreed to make changes to how it sells its laptops
The tool replaces SSL certificates without validating them first, opening the door to man-in-the-middle attacks
A third-party, man-in-the-middle proxy used by Superfish is also used in other apps
The company confirmed that a software program preloaded on some of its laptops exposes users to potential attacks
Superfish software installed on Lenovo computers uses a self-generated root certificate to intercept HTTPS communications