Crippled isn't the word. They broke browser cryptography. The Superfish MitM proxy on the host is validating any cert it gets, even patently bogus ones. As a result it's possible for a networked MitM who is actively going after SSL/TLS traffic to see all traffic with no need to have the Superfish private.
Here's a screenshot of what their MitM proxy provides back to the browser for a compromised connection to Bank of America:
Note that my MitM proxy cert is one gen'd with OpenSSL and is not the Superfish private! While it's cool that the private can be extracted, given the failure of the Superfish software to properly validate the public in the SSL/TLS handshake, the Superfish private isn't something a bad guy needs to get in the middle of encrypted traffic.
Once Lenovo was bought by a chinese company... didn't everyone kind of assume the state of China would use this opportunity to do what the NSA does for American hardware? The extent of the NSA's actions weren't known at the time, but you had to assume China would be less bound by restrictions.
Here's a screenshot of what their MitM proxy provides back to the browser for a compromised connection to Bank of America:
https://defaultstore.com/four.png
Note that my MitM proxy cert is one gen'd with OpenSSL and is not the Superfish private! While it's cool that the private can be extracted, given the failure of the Superfish software to properly validate the public in the SSL/TLS handshake, the Superfish private isn't something a bad guy needs to get in the middle of encrypted traffic.