In 2015 Lenovo shipped laptops with software that broke HTTPS for every user.
Installed deliberately for ad revenue.
Lenovo pre-installed a piece of adware called Superfish on consumer laptops starting September 2014. Its purpose was to scan every image you view on the internet and inject ads for similar products.
To do that on HTTPS pages, it needed to intercept your encrypted traffic.
So it did something catastrophic.
it installed itself as a trusted root certificate authority on your laptop. Meaning your browser treated Superfish as a trusted source of certificates, the same level of trust as VeriSign, DigiCert, or your bank's own certificate authority.
Everything you did over HTTPS- banking, email. shopping. medical records was being decrypted by Superfish, analyzed for images, and re-encrypted before it reached you.
then it got worse.
Every Lenovo laptop shipped with the exact same certificate and the exact same private key.
The password protecting that private key was cracked in three hours by Security researcher, Rob Graham (Errata Security).
The password was "komodia."
The name of the Israeli company that made the code.
Once cracked, anyone with that private key could impersonate any website to any Lenovo user on earth. your bank. your email. any HTTPS site. a fake page would show a valid padlock and your browser would trust it completely.
Lenovo's initial response: "we have thoroughly investigated this technology and do not find any evidence to substantiate security concerns."
Then the password was posted publicly online.
Lenovo paid $7.3 million to settle the class action lawsuit.
The EFF called it "catastrophically irresponsible."
Crazy stuff.
Now do Lenovo/Superfish. They broke security so they could watch your internet browsing, and inject ads into other site's web pages. Even over HTTPS.
They used a trusted root certificate, with a private key protected by a weak password, allowing anyone to decrypt your traffic.