Elektrine lite

← Feed

@Manjushri@piefed.social

Post #2153254

2026-03-21 00:38 UTC

I've been twitchy about Lenova since they got caught [selling computers with a rootkit that reinstalled crap-ware that users had uninstalled](https://www.zdnet.com/article/lenovo-rootkit-ensured-its-software-could-not-be-deleted/). A user would uninstall useless software from their computer, and when they rebooted, the rootkit would kick in and reinstall the bloatware. >The "rootkit"-style covert installer, dubbed the Lenovo Service Engine (LSE), works by installing an additional program that updates drivers, firmware, and other pre-installed apps. The engine also "sends non-personally identifiable system data to Lenovo servers," according to the company. The engine, which resides in the computer's BIOS, replaces a core Windows system file with its own, allowing files to be downloaded once the device is connected to the internet. >But that service engine also put users at risk. >In a July 31 security bulletin, the company warned the engine could be exploited by hackers to install malware. The company issued a security update that removed the engine's functionality, but users must install the patch manually. They had previously been caught selling computers with adware installed on them. >Earlier this year, the computer maker was forced to admit it had installed Superfish adware over a three-month period on new machines sold through retail channels. The adware had the capability to intercept and hijack internet traffic flowing over secure connections, including online stores, banks, among others. >Users were told they should "not use their laptop for any kind of secure transactions until they are able to confirm [the adware] has been removed," security researcher Marc Rogers told ZDNet at the time. >It was thought as many as 16 million consumers and bring-your-own-device users were affected by the preinstalled adware.

Replies (1)

  • @MonkderVierte@lemmy.zip 2026-03-21 11:31

    > since they got caught selling computers with a rootkit Is there any large computer/phone vendor that didn't? Tuxedo maybe, but they aren't large. No excuse, but preinstalled malware is more "common" than you think, and sometimes one of them is a rootkit/bootkit. (paid-for) bloatware is often not quality-checked; it's handled similiarly to ad platforms.

    Open ##2153256