Lenovo's file-sharing app actually used this terrible password

Bad password

Lenovo has just patched up a piece of its software to remove major security flaws which included a rather unbelievable password blunder.

By now, we're all used to the regular articles about how Joe Public's password practices are terrible, but you wouldn't expect a computing giant like Lenovo to use a default password that made the worst passwords of 2015 list for one of its apps.

Unfortunately, as Core Security spotted, that's exactly what Lenovo did with its ShareIt app for Windows and Android, a program that allows file sharing between PCs and phones/tablets, which comes with a default password which is the same for every user when it sets up a Wi-Fi hotspot in order to facilitate the transfer of files.

And that default password was: '12345678'. Which just happens to be third place on the latest stupid passwords list (only bested by the slightly less secure because it's shorter '123456', and that old chestnut 'password').

In other words, anyone could connect to the hotspot via a device with Wi-Fi, either knowing the password was this, or simply by guessing the password given its eminently guessable nature, and subsequently view the files (via an HTTP Request to the web server launched by the program).

No encryption

Core Security also noted that the files being shared were transferred via HTTP with no encryption used, a further vulnerability which is obviously bad news and could potentially allow an attacker to view the data being transferred.

However, as we said at the outset, the good news is that all this has now been changed with the latest patch – so if you use ShareIt, do make sure you update to the latest version.

ShareIt is used for quick and convenient file sharing by some 30 million folks across the world.

Via: PC Gamer

TOPICS

Darren is a freelancer writing news and features for TechRadar (and occasionally T3) across a broad range of computing topics including CPUs, GPUs, various other hardware, VPNs, antivirus and more. He has written about tech for the best part of three decades, and writes books in his spare time (his debut novel - 'I Know What You Did Last Supper' - was published by Hachette UK in 2013).

Latest in Computing Security
Dark Web monitoring
How users benefit from Dark Web monitoring
The X logo next to a silhouette of Elon Musk
Who was really behind the massive X cyberattack? Here’s what experts say about Elon Musk’s claims
A person holding a phone looking at a scam text with warning signs around
A massive SMS toll fee scam is sweeping the US – here’s how to stay safe, according to the FBI
View on National Assembly building in Paris, France, with French and European flags flying.
France rejects controversial encryption backdoor provision
ensure data security for your business
The complete data protection system for your business
ignal messaging application President Meredith Whittaker poses for a photograph before an interview at the Europe's largest tech conference, the Web Summit, in Lisbon on November 4, 2022.
"We will not walk back" – Signal would rather leave the UK and Sweden than remove encryption protections
Latest in News
DeepSeek
Deepseek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring