10 ms·
Lenovo crams unremovable crapware into laptops by hiding it in the BIOS (2015)
- usr1106 7y agoDoesn't affect me because I have not run Windows for 10 years. I install Windows on every PC. I would prefer to run ARM more wideley, but unfortunately the hardware choice is limited. That said I am not overly confident that with Linux I am totally immune against executing code I never intended to. The kernel needs to cooperate with the BIOS. I would not been surprised if the BIOS can make it execute arbitrary code provided by the vendor. It just needs to be a bit more tricky than telling the operating system look here is a binary in RAM, please save it on root file system as /bin/init
- bluecmd 7y agoYou don't even need that. The BIOS can just install vulnerable SMM handlers and then you're screwed. I don't get why you say it doesn't affect you - bloated and crappy firmware affects everyone, regardless of OS.
- usr1106 7y agoThe described mechanism does not affect me, because Linux kernel or any distro does not take a binary from RAM and installs it into the rootfs. I don't claim that Linux could not be made to execute arbitray code injected by the BIOS. So far I am somewhat optimistic that no HW vendor does it, it's a bit more tricky because different from Windows Linux does not offer a specified API to do such installation. With enough dedication and effort the BIOS could install programs to be run every boot also in Linux. I have no illusions that Linux prevents that (unless you use image signing, dm_verity and whatnot), I am just somewhat optimistic PC vendors don't bother to make the effort required.
- em-bee 7y agobut they could put a custom linux kernel into the firmware that boots before your installed one, which can access the disk and write to it. in fact weren't there mainboards with linux in the firmware already? they weren't doing nefarious things, but they could have.
- usr1106 7y ago> The BIOS can just install vulnerable SMM handlers and then you're screwed. Writing SMM handlers is not an easy job. Using the API provided by Windows to make installations as described by the article is an easy job. The installed program is just plain simple user space code that can use all services of the operating system. No special skills required to make it phone home. Are there any reports of an SMM handler able to phone home? (Honestly curious)
- usr1106 7y ago>install vulnerable SMM handlers How can an SMM handler be vulnerable? The biggest problem with SMM is that they run in ring -2. Nothing on the machine can see what they are doing. Well, they are using memory, if you can manipulate the memory they are using you can manipulate what the handler does, even if you cannot see it executing. But wasn't that the hole closed in 2011? https://www.theregister.co.uk/2015/08/11/memory_hole_roots_intel_processors/ https://www.theregister.co.uk/2015/08/11/memory_hole_roots_i... This is fascinating to discuss or very worrying to use. That's why I wrote I'd prefer ARM over Intel any time. It just does not have such a horrible mess of BIOS, SMM, ME and whatnot taking control away from the programmer/machine owner. But setting a simple Windows API like WPBT described in the article in relation to SMM is comparing apples and oranges. Linux has nothing comparable to WPBT, but of course it cannot be more trustworthy than the Intel/PC platform to begin with. For a dedicated 3 letter agency that's probably equivalent to not at all, but for the average PC vendor trying to force their idea of "user support" on you it's a sufficient hurdle, I'd hope.
- Vrondi 7y agoIf it's in the BIOS, it doesn't matter what OS you use. The BIOS powers up first and is active before the operating system ever is.
- tinus_hn 7y agoExcept only Windows cares to actively look for the Windows program offered by the BIOS and run it.
- usr1106 7y agostupid mistake, sorry > I install Windows on every PC Linux of course
- basicplus2 7y agonot sure why anyone in the know would ever buy lenovo.. Also cannot believe IBM compromised themselves being involved with Lenovo with their pc's and legacy servers like systemx https://systemx.lenovofiles.com/help/topic/com.lenovo.systemx.common.nav.doc/overview_rack_servers.html?cp=0_2 https://systemx.lenovofiles.com/help/topic/com.lenovo.system...
- areoform 7y agoSome of my highest rated comments were for Apple's recent failures. Their laptops shipped with an unworkable keyboard. New product lines were confusing. The existence of the MacBook alongside the MacBook Air defied logic. Their "pro" machines were no longer pro. The list went on. Apple has changed some of that, but even if they don't, my next laptop will still be a Mac. Because Apple doesn't install shit on my machine. Apple fixes security holes. Apple doesn't cheat me on my privacy when I buy a machine. Apple might suck donkey balls but everyone else sucks even more. Pardon my French.
- elorant 7y agoThen buy a Linux laptop. Problem(s) solved. I can't understand some of you guys. You pay 2k for a laptop which has a shitty keyboard and then you look for excuses to justify your decision. Sure, a lot of what you mention about Windows machines is true. But they're also preventable with work arounds. What kind of a work-around is there for the problem with MacPros keyboards? I have a Toshiba laptop (Tecra Z40). Aside from the crap they install to make their tailor-made hardware to work everything else is stellar. The machine works for the last two years problem free, and it will probably keep working for another five. Don't make it sound like every non Apple laptop is crap because it isn't.
- acqq 7y ago> Then buy a Linux laptop. Problem(s) solved. I use Linux on the notebooks since around 2003. The problems are far from being solved, from my experience: - There was constantly some piece of hardware that wasn't supported. - There were constantly pieces of operating system and user space that were simply broken until a lot of manual work is applied. - The brokenness increases with every update. At the start I didn't use LTS (I don't even remember if the LTS versions even existed for the distro I've used) -- it was a major pain. Six months go by, new upgrade, everything's broken. Search the internet, ask: "oh you upgrade an existing installation? It's not tested, you should installed blank and copied your data, we do that" -- oh thanks. - The brokenness of power saving is amazingly persistent. Linux notebooks typically worked acceptable only when plugged in. - Even worse, the brokenness of the possibility of playing the stutter free videos: https://xkcd.com/619/ https://xkcd.com/619/ I have still that problem (it was not only "flash" that was and is the problem!) and discovered that the "lighter" compositors that are advertised as supposedly needing less resources made even worse results. I still have computers that in 2019 with the latest Linuxes can't play videos normally, whereas on the same computer videos in Windows play perfectly. In short, if you need a computer only for a very reduced set of tasks and are ready to spend the time "fixing" the remaining issues, Linux can work for you. But don't expect "problems solved." On another side using Windows brings its own crazy pains: if you keep even the Windows provided "antivirus" solution on, even file copying can be orders of magnitude slower than what the machine would be able to do. Plus the crapware. And the exposure to many more viruses trojans etc. Or even the ads built in in the OS. So what's then left? Apple. Also not perfect, of course, but some problems are actually "solved" from the start. But using Apple computers brings its own issues and, of course, prices. It's just the question which kinds of problems you want to be exposed to. I personally can't stand not being able to reasonably easy replace a hard disk in my notebook. I don't even know what I can buy the next time.
- redprince 7y agoFor what it's worth, the professional equipment marketed under the "Think" brand was not affected by this. It was only ever a problem for their consumer line of devices. https://news.lenovo.com/pressroom/press-releases/lenovo-statement-on-lenovo-service-engine-lse-bios/ https://news.lenovo.com/pressroom/press-releases/lenovo-stat... In general the Intel platform is quite the horror show of complex, deeply embedded layers of closed source software outside of the control of the user or the operating system. All the while these components have full control over the machine and all software running on it. Intel ME, AMD PSP, the UEFI BIOS were just some sources of vulnerabilities coming with the hardware. So just buying another brand of laptop, PC or server won't do. There would need to be a fundamental shift towards handing back the user or owner full control over what is executed on his machine.
- tonyedgecombe 7y agoFor what it's worth, the professional equipment marketed under the "Think" brand was not affected by this That doesn't make it OK.
- redprince 7y agoIt should go without saying that it isn't okay. But thank you for helping the people with broken moral compasses.
- CaptainZapp 7y agoCertainly not ok, but very helpfuj. I sure as shit will never, ever buy anything Lenovo. Pro or otherwise.
- api 7y agoI still wont buy them as the entire brand is tainted by this customer hostile crap.
- Jemm 7y agoMy brand new Lenovo has no crapware at all. It had McAffee (now owned by intel) but that was easy to remove. Compared to Samsung who put a non removable Facebook app on their A50 phone I am happy with my Lenovo. The Samsung -home went back not only because of the Facebook app but also because the fingerprint reader did. To work better than 10% of the time and the digitizer was horrible.
- noja 7y ago> My brand new Lenovo has no crapware at all. It had McAffee McAfee is crapware. > Compared to Samsung who put a non removable Facebook app adb shell pm uninstall -k --user 0 com.X
- runlevel1 7y agoMcAfee was actually spun back out of Intel in 2017.
- tinus_hn 7y agoIt had no crap at all, except for this crap.
- josteink 7y agoTo be fair this crapware affected Windows users only, and was removed swiftly in a quickly issued BIOS update after this caused a PR nightmare... back in 2015. So why are we discussing this now, almost half a decade later? Why is this suddenly relevant again?
- i_am_proteus 7y agoBecause there are a lot of people who really like Macs and there are a lot of people who really like things that aren't Macs and these people do seem to enjoy engaging with/against each other.
- Wowfunhappy 7y agoSo, how can I disable the Windows functionality that makes this type of thing possible? Surely there's a way?
- Vrondi 7y agoNo. Windows does not control the BIOS. The BIOS activates when the machine is powered on, before the operating system becomes active. This is at the hardware maker level, and outside the control of Windows.
- ndidi 7y agoThe article mentions how Windows reads an ACPI table, looks for a specific executable file, and willingly runs it. It's not the BIOS forcing anything to happen, Windows goes out of its way to look for an .exe that is bundled in the BIOS and then happily runs it.
- peter_d_sherman 7y agoHere's a writeup on what I've been able to piece together (thus far) on this: https://pastebin.com/wLyjNvFC https://pastebin.com/wLyjNvFC Note that it this rootkit/malware seems to be somewhat independent of manufacturer, that is, it's not just Lenovo but several other prominent laptop manufacturers where the same phenomena occurs...
- Toren93 7y agoАга
- Toren93 7y agoБред
- tinus_hn 7y agoThe issue is with Microsoft forcing this ridiculous behavior.