Anti-theft software could create security hole

July 31, 2009 By JORDAN ROBERTSON , AP Technology Writer laptop

(AP) -- A piece of anti-theft software built into many laptops at the factory opens a serious security hole, according to research presented Thursday.

The "Computrace" software, made by Vancouver-based Absolute Software Corp., is part of a subscription service that's used to find lost or stolen computers. Many people don't know it's on their machines, but it's included in computers from the biggest PC makers.

The software is built into computers at the factory because that embeds it so deeply that even the extreme act of uninstalling the operating software won't delete it. The software is included in a part of the computer known as the BIOS, which refers to programs used to boot the computer.

The service Absolute sells can be valuable because sensitive data can be purged remotely from a stolen machine. The computer is still able to reach out to a specially designated Web site for instructions even if a criminal is tampering with the machine.

But research by Alfredo Ortega and Anibal Sacco with Boston-based Core Security Technologies, and presented Thursday at the Black Hat security conference here, shows it can cut two ways.

If a criminal has infected a computer that has the Computrace technology, he can take deep control of a machine.

That's because he's able to modify the computer's settings to maintain a connection with that machine even if the is uninstalled then reinstalled - an extreme way, but sometimes the only way, to make sure a computer is cleaned of viruses.

"You have something that's pre-installed, and considered non-malicious, that you can manipulate and turn into a - that's pretty unique," said Ivan Arce, Core Security's chief technology officer.

Arce said Absolute can fix the problem with an update to the software that is then pushed out to affected computers. He added that users can disable the software's ability to be a problem on their own, too. It takes some technical know-how, though.

"It's not hard to block once you know what to look for," Arce said.

Absolute spokesman Craig Clark said the company would comment after Core's presentation Thursday, but then did not make anyone available. He said Absolute's technical team "needs to understand the concerns Core has raised before they can speak to it accurately."

Roel Schouwenberg, a senior antivirus researcher with Kaspersky Lab, said the vulnerabilities Core Security found could be a "pretty big challenge for the security community" if they're exploited. But he added that the special access a hacker can get is undermined somewhat by the fact malicious programs they try to download still have to come into the the same way they always do, and can be protected against.

Any files that download "will not be stealth, they will not be hiding, they will be visible on the system," Schouwenberg said. "Anti-malware () will be able to scan them. It could have been a whole lot worse."

---

On the Net:

View Core Security's research paper at:

http://www.coresecurity.com/content/Deactivate-the-Rootkit

©2009 The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.


print this article email this article download pdf blog this article bookmark this article     Stumble it Digg this share on Facebook retweet share on Reddit add to delicious
Rate this story - 5 /5 (2 votes)

Rank Filter

Move the slider to adjust rank threshold, so that you can hide some of the comments.


Display comments: newest first

  • AshleyFromAbsolute - Aug 02, 2009
    • Rank: not rated yet
    I work for Absolute Software. The claims that there's a vulnerability in Computrace are without merit and systems are secure:

    - The Computrace BIOS module does not allow a special undetected path into the operating system.
    - In order for the Computrace BIOS module to work, it is activated by the end-user customer, not the computer manufacturer, upon receipt of the computer and activation of Absolute Software's products.

    - The Computrace BIOS code alleged in the article to have this vulnerability is old code that was not officially released into a BIOS and, to Absolute's knowledge, has never been active in the BIOS of any computer.

    - If a malicious attacker were able to alter the BIOS code, any popular anti-virus software would alert the customer.

    - The Computrace BIOS module currently on the market is not susceptible to the risks claimed in the article and therefore none of our customers are at risk for this specific type of attack

    For more detailed info: http://ow.ly/iQdj

July 31, 2009 all stories

Comments: 1

5 /5 (2 votes)
  • Stumble this up

  • Digg this

  • share this

  • hide
  • Related Stories

  • Microsoft warns of serious computer security hole
    created Jul 06, 2009 | popularity not rated yet | comments 0
  • Grisoft Offers Free Rootkit Removal
    created Apr 11, 2007 | popularity not rated yet | comments 0
  • Glitch in antivirus software troubles PC users
    created Jul 10, 2009 | popularity not rated yet | comments 0
  • Researchers develop next-generation computer antivirus system
    created Aug 06, 2008 | popularity not rated yet | comments 0
  • $100 Laptop May Be at Security Forefront
    created Oct 09, 2006 | popularity not rated yet | comments 0



  • hide
  • Relevant PhysicsForums posts

  • Control System
    created 1hour ago
  • Base Isolation Systems in Skyscrapers?
    created 15 hours ago
  • Need to interview a Computer Hardware Engineer for school project
    created 17 hours ago
  • transient heat transfer
    created 23 hours ago
  • More from Physics Forums - General Engineering

Other News

NREL Uncovers Clean Energy Leaders State by State

NREL Uncovers Clean Energy Leaders State by State

Technology / Energy

created 5 hours ago | popularity 2 / 5 (2) | comments 1

(PhysOrg.com) -- That California and Texas still lead the United States in generating renewable energy probably is no surprise. But, NREL's 2009 State of the States report shows that several smaller states ...


Opera logo

Stable Opera 10.10 browser with Unite now available

Technology / Software

created 6 hours ago | popularity 4.7 / 5 (3) | comments 2

(PhysOrg.com) -- The web browser Opera 10.10 has been released as a stable version, and it has a number of new features to enhance the browsing experience, including "Unite", which is a group of applications ...


Intelligence inside metal components

Intelligence inside metal components

Technology / Engineering

created 3 hours ago | popularity 4.5 / 5 (2) | comments 0

Up to now, extreme production temperatures made it impossible to equip metallic components with RFID chips during the operating process. At Euromold in Frankfurt (Dec. 2-5), Germany, Fraunhofer researchers ...


Key scientist says politics behind stolen e-mails

Technology / Other

created 6 hours ago | popularity 1 / 5 (1) | comments 4

(AP) -- A leading climate change scientist said hackers breaking into a university's computer server and then posting documents online show the nasty politics of global warming.


Just in time for Black Friday: students turn iPhone into barcode scanner

Just in time for Black Friday: students turn iPhone into barcode scanner

Technology / Software

created 17 hours ago | popularity 4.7 / 5 (3) | comments 0

(PhysOrg.com) -- Comparing prices over the Internet has become a common practice for consumers. Now, just in time for Black Friday, a group of Missouri University of Science and Technology students is putting ...