from Hacker News

Who is "Absolute Persistence", and why is their spyware on 600M computers?

by phkamp on 11/29/24, 10:32 PM with 20 comments

  • by walterbell on 11/30/24, 12:54 AM

    CompuTrace has been shipped by every major x86 PC OEM for decades, for Windows process injection, https://en.wikipedia.org/wiki/Absolute_Home_%26_Office

    > Absolute Home & Office (originally known as CompuTrace, and LoJack for Laptops) is a proprietary laptop theft recovery software (laptop tracking software). The persistent security features are built into the firmware of devices. Absolute Home & Office has services of an investigations and recovery team who partners with law enforcement agencies to return laptops to their owners. Absolute Software licensed the name LoJack from the vehicle recovery service LoJack in 2005.

    There used to be a BIOS option for on/off and "Permanently Disable", but that might have changed in recent versions.

    HP: https://support.hpwolf.com/s/article/Absolute-Software-Activ...

    Dell: yikes, the 2024 version is a permanent one-way, one-time option for Activate or Disable? Need to check status on eBay device purchases. https://www.dell.com/community/en/conversations/inspiron/how...

    Lenovo: that one time we accidentally enabled it, https://support.lenovo.com/us/en/solutions/ht105220-unintend...

    Apple x86 laptops: shipped an Arm microcontroller (T2 Security Enclave) to assert control of interactions between x86 CPU and disk storage, until they could replace the CPU with Apple Silicon.

    HN ranking history for this thread: https://hnrankings.info/42277714/

  • by M95D on 11/30/24, 6:09 PM

    I had it in Lenovo X61 Tablet. It was called CompuTrace back then. It was a BIOS module that Windows executes while processing ACPI tables during boot. Now it's probably a UEFI module that does the same.

    I removed it by 0-ing out the module in a BIOS update image and reinstalling Windows. This method probably doesn't work with UEFI anymore because it invalidates the signature, so yes, it's unremovable.

  • by yencabulator on 12/5/24, 4:23 PM

    It seems the "persistence" part depends on a Windows installation doing something specific. The year of Linux on the Laptop!
  • by phkamp on 11/29/24, 10:32 PM

    I have never seen a single article anywhere mention this company or their factory installed spyware. Why ?
  • by yodon on 11/30/24, 2:13 AM

    Is this advertising campaign of theirs new?

    It seems like an absolutely terrible idea for a campaign "hey everyone - our company has been wildly successful at putting spyware on hundreds of millions of machines and no one even knows our name!"

  • by Animats on 11/30/24, 1:01 AM

    So who's exploiting this now? Exploits were known back in 2014.

    Could a manufacturer placing this on a PC be considered material support of terrorism?

  • by JSDevOps on 11/29/24, 10:33 PM

    Never heard of it