Lenovo collects usage data on ThinkPad, ThinkCentre and ThinkStation PCs
computerworld.com
computerworld.com
However, that's no guarantee to help you escape this kind of malware. Even if you replace the hard drive and put an open source OS on a laptop, you're still booting from an increasingly complex, opaque blob of UEFI firmware that you can't get rid off in most consumer devices. Who knows what goes on in there?
Then you've got the NIC firmware, the TPM (which is basically an entirely separate computer), and for corporate laptops often Intel's vPro stack as well.
Realistically, if a vendor wants to track or trick you, they'll always have the means to do so.
And if the past few years have taught us anything, it's that they really want to track you.
The final piece of the puzzle is the new "Software Guard Extensions" in Intel's latest CPUs. This is clearly designed to protect SMM[2]. It is going to be a lot harder to "root" this stuff when the RAM is encrypted.
[1] http://www.slideshare.net/codeblue_jp/igor-skochinsky-enpub https://www.youtube.com/watch?v=Y2_-VXz9E-w
[2]...and DRM in general. See this diagram of GlobalPlatform's "Trusted Execution Environment"; in particular, note how the "Rich OS" (windows, linux, etc) is allowed to run outside the chain of trust, with the DRM being protected by hardware. http://i.imgur.com/rjbzWyB.jpg
1. Allow application developers to protect sensitive data
from unauthorized access or modification by rogue software
running at higher privilege levels.
...
5. Enable the development of trusted applications [...]
6, Enable software vendors to deliver trusted applications and updates [...]
...
8. Enable applications to define secure regions of code and data that
maintain confidentiality even when an attacker has physical control
of the platform and can conduct direct attacks on memory.
This isn't about buffer overflows. You don't need to create a system where software vendors can create regions of memory that are protected against a logic analyser or cold boot attack to fix C style pointer bugs. You do need this capability if you want to hide things from the owner of the computer.It's not like they are hiding anything - "trusted applications" has been a dog whistle for DRM at least since "Palladium" (later called "Next-Generation Secure Computing Base"), part of Microsoft's "Trustworthy Computing" plans ~15 years ago.
[1] https://software.intel.com/en-us/blogs/2013/09/26/protecting...
Without his work GNU/Linux would never have happened, yet many that criticize him enjoy using GNU/Linux.
Back then it was not clear if *BSD would manage to win the court case from AT&T.
It really bothers me when people assign this to new technologies in general. Yes, some are actually new in desktops, like SMM. But most have been there for ages and just got an updated name or architecture.
It gathers location data and other nasties.
I asked Lenovo about this but they denied it was malware, but they would not tell me what information it was gathering. Interestingly, initially they denied installing it at all!
That was... Until I pointed them to a press release that showed that they were indeed paying Conduit Client Services...
http://www.businesswire.com/news/home/20140618005930/en/Peri...
Perion later acquired them:
http://www.businesswire.com/news/home/20140102005313/en/Peri...
The case where lenovo were using a UEFI dropper in their consumer machines to reinstall malware after a reinstall was really bad. But what would make me stop buying their machines is if a similar below-the-OS malware/backdoor injection were present in their business thinkpads. Is there any suggestion that this is the case?
Probably not. They're off our purchasing list.
Problem is: now what? Hardware vendors have all turned to crap in the last 5 years. Lenovo ships crapware and poor quality kit now. HP is stupid expensive and even enterprise support is crap. Dell are unreliable as hell. Literally all other vendors won't support a model more than about 6 months old i.e. no part stock, no service, just replacement with another chunk of junk that will fail in a few months (Acer, Asus I'm looking at you mostly).
Just leaves Apple but then they're just glued together folding iPads with keyboards attached now with no chance of maintenance and reliability issues as well. New battery? Get the paint scraper and heat gun out.
I'm using a Lenovo X201 myself with Mint and I suspect this is the last brand laptop I'm going to use. Back to the custom desktops at home.
They've all played the race to the bottom, because nobody evidently believed in the premium PC and that people were willing to pay for that.
When you're constantly pushing prices and margins down for almost a decade, of course quality will suffer.
I wouldn't be surprised if Lenovo decided at some point to also distribute malware modules for Ubuntu as well.
[1] https://www.phoronix.com/scan.php?page=news_item&px=Intel-Bo...
Unfortunately, Lenovo has seriously blotted their copybook in this area & the onus is on them to demonstrate trustworthiness. It’s notable that prior to the Superfish debacle, they didn’t even bother to notify the end-user if the blog post is to be believed.
However:
3 years ago, my department went with Acer V5-571P laptops. Every single one has been broken and destroyed from casual use. We've found serious manufacturing defects and other flaws, and Acer is not interested in fixing it.
5 years ago, however, we had a small batch of Lenovo E430 devices. These devices are in much better shape than the devices two years younger than them. We have a few other groups of 'incremental updates' that have the exact same results. Lenovo devices hold up much better.
Say what you will about Lenovo's shady practices, but their computers are built like tanks.
However, I'm still happy with ThinkPad hardware and I'll still consider them when I need a new laptop. They're the only vendor including a three-button trackpoint, which I enjoy using over a touchpad. They have a nice no-nonsense aesthetic. While the build quality has suffered over the years, they're still sturdy and reliable, more so than most competitors.
I'm also pretty sure they're not the only ones doing this kind of bullshit. They're just doing a poor enough job to get caught in the act.
I've well aware that computers come pre-installed with crap. Shocked to see the tricks being used to keep it there. Maybe I'm just naive...
But the answer to the question "Why do OEM versions of Windows even exist in the first place" is that without OEM customization, a Windows computer is a non-functional computer.
I have reinstalled Windows on quite a few laptops and desktops and have been quite surprised with how much works straight out of the box these days (mostly everything in my experience, bar some stuff like Fn keys). YMMV of course.
Of course you can build SOEs with manually assembled sideloaded drivers, especially if your organization uses just a handful of different models.
I even worked at a few places that created their own UNIX flavors (mostly GNU/Linux based).