Superfish

Superfish
Company typePrivate
IndustryInternet
Founded2006 (2006)
DefunctMay 2015
FateClosed
SuccessorJustVisual.com
Headquarters,
Key people
  • Adi Pinhas (co-founder & CEO)
  • Michael Chertok (co-founder & CTO)
ServicesVisual search[1]
Revenuec. $40 million
Number of employees
90

Superfish was an advertising company that developed various advertising-supported software products based on a visual search engine. The company was based in Palo Alto, California.[1] It was founded in Israel in 2006[2] and has been regarded as part of the country's "Download Valley" cluster of adware companies.[3] Superfish's software is malware and adware.[4][5][6][7][8] The software was bundled with various applications as early as 2010, and Lenovo began to bundle the software with some of its computers in September 2014.[4] On February 20, 2015, the United States Department of Homeland Security advised uninstalling it and its associated root certificate, because they make computers vulnerable to serious cyberattacks, including interception of passwords and sensitive data being transmitted through browsers.[4][9]

History

Superfish was founded in 2006 by Adi Pinhas and Michael Chertok.[2][10] Pinhas is a graduate of Tel Aviv University.[11] In 1999, he co-founded Vigilant Technology, which "invented digital video recording for the surveillance market", according to his LinkedIn profile.[better source needed] Before that, he worked at Verint, an intelligence company that analyzed telephone signals and had allegedly tapped Verizon communication lines.[12] Chertok is a graduate of Technion and Bar-Ilan University with 10 years of experience in "large scale real-time data mining systems".[13]

Since its founding, Superfish has used a team of "a dozen or so PhDs" primarily to develop algorithms for the comparison and matching of images. It released its first product, WindowShopper, in 2011.[14] WindowShopper immediately prompted a large number of complaints on Internet message boards, from users who did not know how the software had been installed on their machines.[12]

Superfish initially received funding from Draper Fisher Jurvetson, and to date has raised over $20 million, mostly from DFJ and Vintage Investment Partners.[15] Forbes listed the company as number 64 on their list of America's most promising companies.[16]

Pinhas in 2014 stated that "Visual search is not here to replace the keyboard ... visual search is for the cases in which I have no words to describe what I see."[17]

As of 2014, Superfish products had over 80 million users.[18]

In May 2015, following the Lenovo security incident (see below) and to distance itself from the fallout, the team behind Superfish changed its name and moved its activities to JustVisual.com.[19]

Lenovo security incident

Users had expressed concerns about scans of SSL-encrypted web traffic by Superfish Visual Search software pre-installed on Lenovo machines since at least early December 2014.[citation needed] This became a major public issue, however, only in February 2015. The installation included a universal self-signed digital certificate issued by certificate authority; the certificate authority allows a man-in-the-middle attack to introduce ads even on encrypted pages. The digital certificate had the same private key across laptops; this allowed third-party eavesdroppers to intercept or modify HTTPS secure communications without triggering browser warnings by either extracting the private key or using a self-signed certificate.[5][8][20] On February 20, 2015, Microsoft released an update for Windows Defender which removes Superfish.[6] In an article in Slate tech writer David Auerbach compares the incident to the Sony DRM rootkit scandal and says of Lenovo's actions, "installing Superfish is one of the most irresponsible mistakes an established tech company has ever made."[21] On February 24, 2015, Heise Security published an article revealing that the certificate in question would also be spread by a number of applications from other companies including SAY Media and Lavasoft's Ad-Aware Web Companion.[22]

Criticisms of Superfish software predated the "Lenovo incident" and were not limited to the Lenovo user community: as early as 2010, users of computers from other manufacturers had expressed concerns in online support and discussion forums that Superfish software had been installed on their computers without their knowledge, by being bundled with other software.[12]

CEO Pinhas, in a statement prompted by the Lenovo disclosures, maintained that the security flaw introduced by Superfish software was not, directly, attributable to its own code; rather, "it appears [a] third-party add-on introduced a potential vulnerability that we did not know about" into the product. He identified the source of the problem as code authored by the tech company Komodia, which deals with, among other things, website security certificates.[23] Komodia was founded by Barak Weichselbaum, a former programmer for Israel's IDF Intelligence Core.[24] Komodia code is also present in other applications, among them, parental-control software; and experts have said "the Komodia tool could imperil any company or program using the same code" as that found within Superfish.[25] In fact, Komodia itself refers to its HTTPS-decrypting and interception software as an "SSL hijacker", and has been doing so since at least January 2011.[26] Its use by more than 100 corporate clients may jeopardize "the sensitive data of not just Lenovo customers but also a much larger base of PC users".[27] Komodia was closed in 2018.[28]

Products

Superfish's first product, WindowShopper, was developed as a browser add-on for desktop and mobile devices, directing users who hover over browser images to shopping Web sites to purchase similar products. As of 2014, WindowShopper had approximately 100 million monthly users, and according to Xconomy, "a high conversion to sale rate for soft goods". Superfish's business model is based on receiving affiliate fees on each sale.[15]

The core technology, Superfish VisualDiscovery, is installed as a man-in-the-middle proxy on some Lenovo laptops. It injects advertising into results from Internet search engines; it also intercepts encrypted (SSL/TLS) connections.[7][29]

In 2014, Superfish released new apps based on its image search technology.

See also

References

  1. ^ a b Hoge, Patrick (October 21, 2014). "Superfish dives deep into visual search". San Francisco Business Times. Retrieved November 16, 2014.
  2. ^ a b "Microsoft, Lenovo scramble to protect users from Superfish security flaw". CBSnews.com. CBS/AP. February 22, 2015. Retrieved September 11, 2015.
  3. ^ Hirschauge, Orr (December 25, 2013). "Another blow to Israel's 'Download Valley' as Google bans toolbars". Haaretz.com. Retrieved September 11, 2015. Among the companies in Download Valley most likely to be hurt by the change are the startups Revizer, Superfish, CrossReader and the Client Connect division of the company Conduit …
  4. ^ a b c "Alert: Lenovo "Superfish" Adware Vulnerable to HTTPS Spoofing". United States Computer Emergency Readiness Team. February 20, 2015. Retrieved February 20, 2015.
  5. ^ a b Fox-Brewster, Thomas (February 19, 2015). "How Lenovo's Superfish 'Malware' Works And What You Can Do To Kill It". Forbes. Retrieved February 20, 2015.
  6. ^ a b Chacos, Brad (February 20, 2015). "Bravo! Windows Defender update fully removes Lenovo's dangerous Superfish malware". PC World. Retrieved February 20, 2015.
  7. ^ a b Williams, Owen (February 19, 2015). "Lenovo caught installing adware on new computers". The Next Web. Retrieved February 19, 2015.
  8. ^ a b Hern, Alex (February 19, 2015). "Lenovo accused of compromising user security by installing adware on new PCs". The Guardian. Retrieved February 19, 2015.
  9. ^ "U.S. government urges Lenovo customers to remove Superfish software". Reuters. February 20, 2015. Retrieved February 20, 2015.
  10. ^ "Superfish gets $10M for image search". San Francisco Business Times. July 30, 2013.
  11. ^ "Q&A: Adi Pinhas, founder and CEO of tech startup Superfish". San Jose Mercury News. January 2, 2015.
  12. ^ a b c Fox-Brewster, Thomas (February 19, 2015). "Superfish: A History Of Malware Complaints And International Surveillance". Forbes. Retrieved February 21, 2015.
  13. ^ "Executive Profile – Michael Chertok – Co-Founder and Chief Technology Officer, Superfish, Inc". Bloomberg, retrieved. Retrieved February 20, 2015.
  14. ^ Craig, Elise (July 16, 2014). "Superfish Aims to Dominate Visual Search, One Product at a Time". Xconomy. Retrieved November 17, 2014.
  15. ^ a b Craig, Elise (July 16, 2014). "Superfish Aims to Dominate Visual Search, One Product at a Time". Xconomy. p. 2. Retrieved November 17, 2014.
  16. ^ "America's Most Promising Companies". Forbes. January 2015. Retrieved February 21, 2015.
  17. ^ "What Will It Take for Visual Search to Catch On?". eMarketer. November 11, 2014. Retrieved November 17, 2014.
  18. ^ Weiss, Vered (September 3, 2014). "Adi Pinhas' Superfish #1 Fastest Growing Private Software Company in the US". Jewish Business News. Retrieved November 17, 2014.
  19. ^ "After Security Scandal, a Tech Firm Says It's Changing Focus". ABC News. May 28, 2015. Archived from the original on May 29, 2015. Retrieved May 31, 2015.
  20. ^ Valsorda, Filippo (February 20, 2015). "Komodia/Superfish SSL Validation is broken". Retrieved February 25, 2015.
  21. ^ Auerbach, David (February 20, 2015). "You Had One Job, Lenovo". Slate. Retrieved February 21, 2015.
  22. ^ "Gefährliche Adware: Mehr als ein Dutzend Anwendungen verbreiten Superfish-Zertifikat" [Dangerous Aware: More than a Dozen Applications spreading Superfish Certificate]. Heise Security (in German). February 24, 2015. Retrieved May 5, 2015.
  23. ^ "Superfish denies blame in Lenovo security mess". The Mercury News: siliconbeat. February 20, 2015.
  24. ^ Brewster, Thomas (February 20, 2015). "The Company Behind Lenovo's Dangerous Superfish Tech Claims It's Under Attack". forbes.com. Retrieved January 25, 2023. In a brief email conversation with Barak Weichselbaum, Komodia's founder who was once a programmer in Israel's IDF's Intelligence Core,...
  25. ^ "Palo Alto startup points fingers over Lenovo ad software security flaws". Contra Costa Times. February 23, 2015.
  26. ^ "Komodia's SSL Decoder/Digestor product page". Komodia Inc. December 14, 2010. Archived from the original on January 22, 2011. Retrieved February 27, 2015.
  27. ^ ""SSL hijacker" behind Superfish debacle imperils large number of users". ars technica. February 20, 2015.
  28. ^ "About". Komodia. December 13, 2010.
  29. ^ Duckett, Chris (February 19, 2015). "Lenovo accused of pushing Superfish self-signed MITM proxy". DNet. Retrieved February 19, 2015.

Read other articles:

American actor (1913–1996) This article needs additional citations for verification. Please help improve this article by adding citations to reliable sources. Unsourced material may be challenged and removed.Find sources: William Prince actor – news · newspapers · books · scholar · JSTOR (March 2013) (Learn how and when to remove this template message) William PrincePrince in Young Doctor Malone, 1962BornWilliam Leroy Prince(1913-01-26)January 26, …

Rotterdam Open 1987 Sport Tennis Data 16 marzo – 22 marzo Edizione 14ª Superficie Sintetico indoor Campioni Singolare Stefan Edberg Doppio Stefan Edberg / Anders Järryd 1986 1988 Il Rotterdam Open 1987, conosciuto anche con il nome di ABN AMRO World Tennis Tournament 1987 per motivi di sponsorizzazione, è stato un torneo di tennis giocato sul sintetico indoor. È stata la 14ª edizione del Rotterdam Open e fa parte del Nabisco Grand Prix 1987. Si è giocato all'Ahoy Rotterdam indoor sportin…

The Military ranks of Burundi (French: Grades militaires du Burundi) are the military insignia used by the National Defence Force of Burundi. Commissioned officer ranks The rank insignia of commissioned officers. Rank group General / flag officers Senior officers Junior officers Officer cadet  Burundi Army[1]vte Général Lieutenant-général Général-major Général de brigade Colonel Lieutenant-colonel Major Capitaine Lieutenant Sous-lieutenant Jenerai Riyetena jenerai Jenerai ma…

International law firm headquartered in United Kingdom For the surname, see Hammonds (surname). Hammonds LLPHeadquartersLeeds, United KingdomNo. of offices11No. of lawyersApprox. 460 (2010)[1]No. of employeesApprox. 1,015 (2010)[1]Major practice areasFull-service commercial practiceRevenue£118 million (2010)[1]Profit per equity partner£364,000 (2010)[1]Date founded1887Company typeLimited Liability PartnershipDissolved1 Jan…

146th season in existence of Manchester United F.C. Manchester United 2023–24 football seasonManchester United2023–24 seasonOwnerManchester United plc (72.3%)Ineos (27.7% from 24 December 2023)Co-chairmenJoel and Avram GlazerManagerErik ten HagStadiumOld TraffordPremier League8thFA CupFinalEFL CupFourth roundUEFA Champions LeagueGroup stageTop goalscorerLeague: Bruno Fernandes (10)All: Bruno Fernandes (15)Highest home attendance73,612 (v. West Ham United,4 February 2024)Lowest home attendanc…

Historic district in Maryland, United States United States historic placeCatoctin Furnace Historic DistrictU.S. National Register of Historic PlacesU.S. Historic district Show map of MarylandShow map of the United StatesLocationCatoctin Furnace, MarylandCoordinates39°34′35″N 77°26′2″W / 39.57639°N 77.43389°W / 39.57639; -77.43389Built1774NRHP reference No.72000578Added to NRHPFebruary 11, 1972[1] Catoctin Furnace (also known as Catoctin Iron …

Questa voce o sezione sull'argomento pallavolisti non è ancora formattata secondo gli standard. Contribuisci a migliorarla secondo le convenzioni di Wikipedia. Segui i suggerimenti del progetto di riferimento. Yunieska RoblesNazionalità Cuba Altezza185 cm Peso70 kg Pallavolo RuoloSchiacciatrice/Opposto Squadra Šygys Öskemen CarrieraSquadre di club ?-2012 Isla de la Juventud2012-2013 Lokomotiv Biləcəri2013-2014 Azərreyl2015 Al-Ahly2015- Šygys Öskem…

Member of the Cabinet of the United Kingdom For the second-highest-ranking official of the Spanish Ministry of Education, see Secretary of State for Education (Spain). United Kingdom Secretary of State for EducationRoyal Arms of His Majesty's GovernmentIncumbentGillian Keegansince 25 October 2022Department for EducationStyleEducation Secretary(informal)The Right Honourable(within the UK and Commonwealth)TypeMinister of the CrownStatusSecretary of StateMember ofCabinetPrivy CouncilReports to…

For other places with the same name, see List of islands called Oronsay. OrnsayScottish Gaelic nameEilean IarmainOld Norse nameÖrfirirseyMeaning of nameEbb (i.e. tidal) island, from NorseLocationOrnsayOrnsay shown relative to SkyeOS grid referenceNG709125Coordinates57°09′N 5°47′W / 57.15°N 5.79°W / 57.15; -5.79Physical geographyIsland groupInner HebridesArea35 ha (86 acres)Highest elevation46 m (151 ft)AdministrationSovereign stateUnited KingdomCou…

Alcoholic preparation flavored with botanical matter For other uses, see Bitter (disambiguation). An old bottle of Kuyavian Stomach Essence, bitters from Posen, Germany (now Poznań, in Poland) A bitters (plural also bitters) is traditionally an alcoholic preparation flavored with botanical matter for a bitter or bittersweet flavor. Originally, numerous longstanding brands of bitters were developed as patent medicines, but now are sold as digestifs, sometimes with herbal properties, and as cockt…

صخور القمر هو مصطلح يشير إلى الصخور التي تكونت على سطح القمر (التابع لكوكب الأرض).[1][2][3] مصادر الصخور هناك حالياً ثلاثة مصادر لصخور القمر على الأرض: الصخور التي جمعتها بعثات أبولو إلى القمر الأمريكية. العينات المعادة من قبل مهمات الاتحاد السوفيتي القمرية. الصخور …

Christianity-related events during the 5th century See also: Christianity in the 4th century and Christianity in the 6th century For broader coverage of this topic, see Christianity in late antiquity.   Spread of Christianity to AD 325   Spread of Christianity to AD 600 In the 5th century in Christianity, there were many developments which led to further fracturing of the State church of the Roman Empire. Emperor Theodosius II called two synods in Ephesus, one …

2008 Alabama Republican presidential primary ← 2004 February 5, 2008 (2008-02-05) 2012 → ← MEAR →45 pledged delegates to the2008 Republican National Convention   Candidate Mike Huckabee John McCain Mitt Romney Home state Arkansas Arizona Massachusetts Delegate count 26 19 0 Popular vote 227,766 204,867 98,019 Percentage 41.25% 37.10% 17.75% Election results by county.   Mike Huckabee   John McCain …

Station of the Berlin U-Bahn For the street, see Frankfurter Allee. For the Berlin Ringbahn station, see Berlin Frankfurter Allee station. Frankfurter AlleeGeneral informationLocationFrankfurter Allee, BerlinFriedrichshainOwned byBerliner VerkehrsbetriebeOperated byBerliner VerkehrsbetriebePlatforms1 island platformTracks2Train operatorsBerliner VerkehrsbetriebeConnections ConstructionStructure typeUndergroundOther informationFare zoneVBB: Berlin A/5555[1]HistoryOpened21 December 19…

1998 World Weightlifting ChampionshipsMenWomen56 kg48 kg62 kg53 kg69 kg58 kg77 kg63 kg85 kg69 kg94 kg75 kg105 kg+75 kg+105 kgvte Main article: 1998 World Weightlifting Championships The 1998 World Weightlifting Championships were held in Lahti, Finland from 7 to 15 November 1998. The men's competition in the light-heavyweight (85 kg) division was staged on 13 November 1998. Medalists Event Gold Silver Bronze Snatch  Georgi Gardev (BUL) 177.5 kg  Pyrros Dimas (GRE) 1…

Welsh rugby union player (1949–2024) Rugby playerJ. P. R. WilliamsMBE FRCSWilliams in 2009Birth nameJohn Peter Rhys WilliamsDate of birth(1949-03-02)2 March 1949Place of birthBridgend, WalesDate of death8 January 2024(2024-01-08) (aged 74)Place of deathCardiff, WalesSchoolBridgend Boys' Grammar SchoolMillfield SchoolUniversitySt Mary's Hospital Medical SchoolSpouseScilla WilliamsChildren4Occupation(s)Orthopaedic surgeonRugby union careerPosition(s) Full-backAmateur team(s)Years Team A…

Reece OxfordNazionalità Inghilterra Altezza190 cm Peso71 kg Calcio RuoloDifensore, Centrocampista Squadra Augusta CarrieraGiovanili 2008-2011 Tottenham2011-2015 West Ham Utd Squadre di club1 2015-2017 West Ham Utd7 (0)2017→  Reading5 (0)2017→  Borussia M'gladbach3 (0)2017-2018 West Ham Utd1 (0)2018→  Borussia M'gladbach4 (0)2018-2019 West Ham Utd0 (0)2019- Augusta77 (2) Nazionale 2013-2014 Inghilterra U-163 (0)2014-2015 Inghilterra U-…

Guinea Khatulistiwa padaOlimpiade Musim Panas 2020Kode IOCGEQKONKomite Olimpiade EquatoguineaPenampilan pada Olimpiade Musim Panas 2020 di TokyoPeserta3 dalam 2 cabang olahragaPembawa bendera (pembukaan)Alba Mbo NchamaBenjamín EnzemaPembawa bendera (penutupan)N/AMedali 0 0 0 Total 0 Penampilan pada Olimpiade Musim Panas (ringkasan)1984198819921996200020042008201220162020 Guinea Khatulistiwa berkompetisi di Olimpiade Musim Panas 2020 di Tokyo. Awalnya dijadwalkan berlangsung selama mus…

BarbarossaRutger Hauer nei panni di Federico I Hohenstaufen detto il BarbarossaLingua originaleInglese Paese di produzioneItalia, Romania Anno2009 Durata139 min Genereepico, storico, biografico RegiaRenzo Martinelli SoggettoRenzo Martinelli, Giorgio Schöttler SceneggiaturaRenzo Martinelli, Giorgio Schöttler, Anna Samueli ProduttoreRenzo Martinelli Produttore esecutivoRiccardo Pintus, Vlad Paunescu Casa di produzioneMartinelli Film Company International, Castel Film Studios, Na-Comm…

2008 2020 Élections sénatoriales de 2014 dans la Haute-Garonne 28 septembre 2014 Type d’élection Élections sénatoriales Postes à élire 5 sièges de sénateur Rassemblement des républicains de Haute-Garonne – Alain Chatillon Liste Union des démocrates et indépendantsUnion pour un mouvement populaireMouvement démocrate Voix 1 217 42,66 %  Sénateurs élus 3  2 Solidarités et équilibre territorial – Claude Raynal Liste Parti socialistePar…