CompuTrace on non-enterprise devices

Sure, CompuTrace and similar technlogies has it’s place, on some devices owned by some high-security enterprises. I really dislike that OEMs appear to put CompuTrace in ALL (AFAICT) new devices. This is somewhat like how Microsoft has used Secure Boot as an excuse to lock down Windows PCs from loading non-Windows OSes. NIST advice for this doesn’t prevent a local user from selecting the OS they want, however. OEMs should be providing two levels of security, tamper-proof devices, for high-security enterprises, and owner-configurable devices, which let the owner have the ability to configure the silicon/firmware security/privacy features, and install the OS they prefer.

Strange, I thought only companies and governments are allowed to access your device’s CompuTrace phone-home chips and firmware. But it appears that there are multiple companies selling support for this to end-users, see the advertisements here:

https://twitter.com/search?q=computrace&src=typd

Companies: decide carefully if you want to use tracking software on your employees. Or at least do it politely:

OEMs: please make CompuTrace-free model(s) of at least one of your (server, laptop, tablet, and smartphone) product line. Privacy-minded consumers will probably even pay a premium for it.

By now, I would have presumed some privacy-minded activist group like the FSF would have a campaign against this, perhaps as part of their Free Hardware campaign…

https://twitter.com/delroth_/status/679972181061820416

Lenovo: fix your CompuTrace QA, see above.

Modders: If you have disabled CompuTrace module in firmware, perhaps using UEFITool or another tool, please write a quick HOWTO, for others to benefit from, such as above Lenovo user. Thanks in advance!

 

European agreement for Absolute and Lenovo

The Canadian ISV/IHV Absolute Software Corporation is working with the European branch of the Chinese OEM Lenovo, to apply CompuTrace — now called Absolute(R) — silicon/firmware-level tracking technology within Europe. Excerpt of press release:

Absolute Collaborates with Lenovo EMEA to Introduce European Factory Activation

Absolute Software Corporation, the industry standard for persistent endpoint security and data risk management solutions, today announced the Company has entered into an agreement with Lenovo EMEA to introduce European factory activation of Absolute Data & Device Security (DDS) (formerly Absolute Computrace). Under this agreement, Lenovo EMEA will incorporate the automated deployment of Absolute DDS, (which will trigger the activation of Persistence technology by Absolute) through Lenovo’s Imaging Technology Center for its European customers. As part of this factory image, customers can opt to load and activate Absolute DDS onto all of their Lenovo devices before shipment.

“Many of our enterprise customers want their Lenovo devices to be protected while in transit. By installing Absolute DDS and activating Persistence technology, our customers will be able to secure these endpoints before they leave the factory,” said Stefan Larsen, EMEA business development manager, Lenovo. “This agreement also allows our customers to reduce the resources spent on configuring and imaging devices, without compromising best-in-class security.”

“Lenovo’s Imaging Technology Center delivers a customized, out-of-the-box experience for its enterprise customers,” said Geoff Haydon, chief executive officer, Absolute. “We are excited to expand our participation in this program to Lenovo customers in Europe. This agreement represents a tremendous opportunity for us to strengthen our position in the region.”

More information:

https://www.absolute.com/en/about/pressroom/press-releases/2015/absolute-collaborates-with-lenovo-emea-to-introduce-european-factory-activation

So,  some of Lenovo’s enterprise customers are concerned about new computers being stolen or otherwise manipulated before they leave the factory? Who can attack OEM systems at this point in the system? Is this just an issue for Lenovo, or do other OEM’s enterprise customers also have this kind of concern? How does this new Absolute/Lenovo change impact attacker’s ability to attack system before the hardware comes to Europe and Persistence technology gets activated?

I wish OEMs would give me the OPTION to have this feature, not presume all of their systems are sold to enterprises. I wish someone would maintain a list of modern CompuTrace-free systems, for non-enterprise citizens who don’t want it installed, as it is useless, since CompuTrace is only available to enterprises. It seems that their compatibility lists include nearly all modern OEM systems. Hmm, does Purism or Novena have it? Did the old Thinkpads — that are being refurbished with Libreboot and resold by 2 companies– have it?

AMD adds Absolute ComputeTrace support

Today AMD joins Intel in adding Absolute’s CompuTrace technology into their systems:

Absolute collaborates with AMD to extend benefits of persistence technology
Vancouver, Canada: August 18, 2015– Absolute® Software Corporation (TSX:ABT), the industry standard for persistent endpoint security and data risk management solutions for computers, laptops, tablets and smartphones, today announced an agreement with Advanced Micro Devices, Inc. (AMD) to incorporate Persistence® technology by Absolute into AMD chip designs.
Under the terms of this agreement, Absolute and AMD will provide an enhanced security offering by embedding patented Persistence technology directly into AMD x86 APU technologies.
“In the interest of improving the privacy and security of our customers, we have been steadfast in our commitment to evolve security offerings through our technology,” said Roy Taylor, corporate vice president, Alliances, AMD. “We are excited to work with Absolute to leverage its unique Persistence technology by integrating this security functionality into AMD processors.”
“AMD is a long-tenured leader in the semiconductor industry with a keen focus on advancing security offerings on the devices they power,” said Geoff Haydon, chief executive officer, Absolute. “By working together, we can explore new ways to advance Persistence technology and deliver a higher level of data and device security to AMD and Absolute customers.”
Persistence technology by Absolute is embedded into the core of devices at the factory. Once activated, Persistence technology provides a reliable two-way connection so IT can confidently manage mobility, investigate potential threats, and take action if a security incident occurs.

http://www.absolute.com/en/about/pressroom/press-releases/2015/absolute-collaborates-with-amd-to-extend-benefits-of-persistence-technology