• nothingcorporate@lemmy.today
    link
    fedilink
    English
    arrow-up
    15
    arrow-down
    1
    ·
    18 hours ago

    Remember when Lenovo got caught putting a rootkit in their bios? That should have been the end of anyone ever buying from them.

    • NewNewAugustEast@lemmy.zip
      link
      fedilink
      English
      arrow-up
      10
      ·
      edit-2
      18 hours ago

      Remember them pre-installing superfish? Pushing ads into the browser, compromising HTTPS by adding their own root certificate, and it was all kept in the bios so even a wipe of the OS wasnt going to fix it.

      Or their software in the bios that pulled in lenovoo software before windows started?

      Or all the CVE’s their bios had?

      And then there is all the feedback software that they added that ran silently in the background.

      I am not sure they enshitified or just simply always have been shit.

  • village604@adultswim.fan
    link
    fedilink
    English
    arrow-up
    111
    ·
    2 days ago

    I really hope there’s a class action over this. Their software breaking your hardware isn’t a failure of the device and should be a recall instead of a warranty repair.

    • Nik282000@lemmy.ca
      link
      fedilink
      English
      arrow-up
      37
      arrow-down
      1
      ·
      2 days ago

      Lenovo has been absolute trash for a while now. They took the ThinkPad brand and destroyed any reputation it may have had, I’m not surprised by this at all.

      • Final Remix@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        14 hours ago

        What’s left? I’m still rocking the same thinkpad since 2015 but it’s really struggling these days (almost time for Linux)

    • yeahiknow3@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      26
      arrow-down
      1
      ·
      edit-2
      1 day ago

      Remember when Lenovo pre-installed spyware on every laptop for years? Dell did the same thing. These “tech” companies are actively detrimental to technology as a concept.

      To Dell, Lenovo, HP, any sign of technological progress is taken as an opportunity to cheat and steal.

      • NewNewAugustEast@lemmy.zip
        link
        fedilink
        English
        arrow-up
        4
        ·
        19 hours ago

        Lets not forget that in doing so, a self-signed root HTTPS cert was put into the windows store creating a man in the middle for ALL https connections.

        When a user visits a web site, the software intercepted the connection, created a fake cert on the fly for that domain and signed itself with a private key.

        WORSE! The private key was the same across ALL laptops and extracting the keys were trivial, so an attacker could own them all.

        Lenovo: go fuck yourself.

    • Fmstrat@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      22 hours ago

      You never know, they might step up. Reports like these in early stages are tough, because the one individual reddit user who was given a quote could have reported the issue before Lenovo can determine if it really is thr BIOS update.

      My guess is, in two weeks or so they make good for affected users.

      • Swordgeek@lemmy.ca
        link
        fedilink
        English
        arrow-up
        2
        ·
        19 hours ago

        Sure, they might. And everyone will forget about it again.

        But they tried to get away with this bullshit, and that defines who they are, not what they back down to.

        • Fmstrat@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          17 hours ago

          tried to get away with

          While this a likely scenario, it’s also unproven. The rep that one person contacted may have had no idea what was going on.

    • BCsven@lemmy.ca
      link
      fedilink
      English
      arrow-up
      2
      ·
      15 hours ago

      Not sure about the hand held but the corporate lenovo I was given autoupdates everything untile I went through and uninstalled the lenovo software center

    • 87Six@lemmy.zip
      link
      fedilink
      English
      arrow-up
      4
      ·
      20 hours ago

      No idea but I know Windows does. A Fx505DT laptop I had bricked itself with a windows-triggered bios update. Warranty covered it but I went a month without a laptop.

  • D06M4@lemmy.zip
    link
    fedilink
    English
    arrow-up
    19
    arrow-down
    1
    ·
    edit-2
    1 day ago

    Prevention: blocking Windows Update.
    Solution: rolling back to a previous BIOS version.

    Too bad most people who purchased a Legion Go won’t know how to do any of that.

    This article has a bit more on the matter.

    Seems people with a Linux distro avoided the whole ordeal. Good for them. 🫶

  • Brem@lemmy.world
    link
    fedilink
    English
    arrow-up
    35
    arrow-down
    4
    ·
    2 days ago

    Checks notes

    1. DO NOT update anything unless completely necessary

    ^Oh, that’s rule no. 2

  • Madzielle@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    21
    ·
    2 days ago

    I have one of these. Ive been manually shutting it down because it wants to update, I never update. But evenutally, the machine just pushes it through anyway on start.

    I swear to gawd if it breaks my legion I will be pissed. It’s the most expensive single item I own.

    • Broadfern@lemmy.world
      link
      fedilink
      English
      arrow-up
      24
      ·
      2 days ago

      Maybe. I know someone who wiped their Legion clean and installed an Arch-based OS and still had the BIOS-brick issue. No idea if they managed to fix it themselves yet but it’s not purely a Windows problem.

      • Beacon@fedia.io
        link
        fedilink
        arrow-up
        37
        ·
        2 days ago

        Yeah BIOS use happens at startup before the OS starts getting involved. While it’s potentially possible that the bug was only in the windows updater, it’s equally possible that it’s present in both, or just Linux. Any OS is equally as able to install a faulty BIOS update.

      • MonkderVierte@lemmy.zip
        link
        fedilink
        English
        arrow-up
        2
        ·
        edit-2
        1 day ago

        How? Did they use fwupd? It’s also not integrated into some kind of auto-update on Arch (unlike Fedora for example).

  • altkey (he\him)@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    2
    ·
    2 days ago

    I wonder how regular users even get to know there’s a bios update. Were they nudged by win11 downloading it for them? Did they have any agency in the process?