• NewNewAugustEast@lemmy.zip
    link
    fedilink
    English
    arrow-up
    4
    ·
    23 hours ago

    Lets not forget that in doing so, a self-signed root HTTPS cert was put into the windows store creating a man in the middle for ALL https connections.

    When a user visits a web site, the software intercepted the connection, created a fake cert on the fly for that domain and signed itself with a private key.

    WORSE! The private key was the same across ALL laptops and extracting the keys were trivial, so an attacker could own them all.

    Lenovo: go fuck yourself.