752
submitted 6 months ago by floofloof@lemmy.ca to c/technology@lemmy.world
top 50 comments
sorted by: hot top controversial new old
[-] CaptDust@sh.itjust.works 371 points 6 months ago

When you turn on your PC and notice that there’s a huge Christmas banner on your desktop, do not panic – your device is not compromised.

Hah, well a vendor just pushed unapproved executable to the device and ran it without consent. Under any definition or other context it's definitely compromised.

[-] user224@lemmy.sdf.org 41 points 6 months ago

Welp, seems ASUS motherboards also push this by default: https://www.techpowerup.com/248827/asus-z390-motherboards-automatically-push-software-into-your-windows-installation

During testing for our Intel Core i9-9900K review we found out that new ASUS Z390 motherboards automatically install software and drivers to your Windows 10 System, without the need for network access, and without any user knowledge or confirmation. This process happens in complete network-isolation (i.e. the machine has no Internet or LAN access).

load more comments (6 replies)
[-] conciselyverbose@sh.itjust.works 369 points 6 months ago

If it's unwanted, disruptive, and (allegedly) impacts performance, that's not "malware-like". It's malware.

[-] nokturne213@sopuli.xyz 206 points 6 months ago

Confirmed, windows 11 is malware.

load more comments (17 replies)
[-] Leate_Wonceslace@lemmy.dbzer0.com 18 points 6 months ago* (last edited 6 months ago)

~~I think the title indicates that it's like the malware known as "Christmas.exe".~~

Edit: I have too much faith in humanity..

[-] conciselyverbose@sh.itjust.works 72 points 6 months ago

The title is pushing the narrative that "real companies" doing hostile bullshit isn't "real malware".

When companies ship malware, it should be called malware.

[-] floofloof@lemmy.ca 29 points 6 months ago* (last edited 6 months ago)

From the article:

Even worse, the malware-looking Christmas wreath is linked to a process called “Christmas.exe.”

So the process was actually called that. It popped up on my machine this morning and I immediately started scanning the whole system for malware and searching to see if anyone else had this problem.

load more comments (1 replies)
[-] FireWire400@lemmy.world 162 points 6 months ago* (last edited 6 months ago)

Who green lit this? I really hope that person gets fired immediately.

The lack of any visual link to ASUS isn't even the biggest problem for me; it's that ASUS rolls out a program that (presumably) puts itself in autostart by default and just pops up without prompt at all.

Edit: There's a fucking setting in the BIOS to auto-install ASUS' bullshit software? And it's enabled by default.... jesus fucking christ

[-] equivocal@lemm.ee 54 points 6 months ago* (last edited 6 months ago)

Most computers firmware can store a Windows executable. Microsoft pushed for an addition to the ACPI tables called WPBT. That stores a Windows exectuable in the firmware. It is of course totally used for the intended purpose...

[-] drspod@lemmy.ml 47 points 6 months ago

I'm always dismayed but not surprised by how many people don't know about Windows Platform Binary Table, which has existed since Windows 8. It's not exactly the type of feature that Microsoft or the board vendors would want to publicize, seeing as it gives them persistent rootkit capabilities on the same level as UEFI rootkits.

Most normal people's model of Windows security is "if something goes wrong then I wipe the disk and reinstall Windows," and WPBT completely breaks that model, and has been doing so for 12 years.

Thankfully there are ways to disable it:

https://github.com/Jamesits/dropWPBT

load more comments (7 replies)
[-] MonkderVierte@lemmy.ml 134 points 6 months ago* (last edited 6 months ago)

It is a part of the ASUS Armoury Crate software that is pre-installed on some ASUS PCs.

Always flash new OS if you buy a computer.

[-] Link@rentadrunk.org 119 points 6 months ago* (last edited 6 months ago)

That won’t get rid of it unless you also manually go into the BIOS and disable the install ASUS Armoury Crate setting as explained in the article.

If you don’t do this it will automatically reinstall even on a fresh install of Windows. Some of these bloatware programs will even install without an internet connection! This absolutely ludicrously stupid feature is called WPBT and is used by lots of manufacturers. Luckily it doesn’t work on Linux (at least for now…).

[-] MimicJar@lemmy.world 53 points 6 months ago

That's wild that it's a BIOS setting. Just an extra level of fuck you.

load more comments (3 replies)
[-] horse_battery_staple@lemmy.world 19 points 6 months ago

I don't think it reinstalls itself if you install Linux

load more comments (1 replies)
load more comments (5 replies)
[-] Appoxo@lemmy.dbzer0.com 20 points 6 months ago

This will be executed even on new fresh installation oob.

[-] MonkderVierte@lemmy.ml 15 points 6 months ago* (last edited 6 months ago)

Yet another vendor-bootkit?

load more comments (1 replies)
load more comments (12 replies)
[-] jaxiiruff@lemmy.zip 63 points 6 months ago

You just cant make this shit up. Truly is year of the linux desktop.

[-] SplashJackson@lemmy.ca 23 points 6 months ago
[-] masterofn001@lemmy.ca 50 points 6 months ago
[-] HeyJoe@lemmy.world 18 points 6 months ago

I don't use Linux much, and I still agree. If the market share for Linux continues to rise every year, then it's absolutely true.

load more comments (1 replies)
load more comments (1 replies)
[-] schizo@forum.uncomfortable.business 62 points 6 months ago

I'd love to know if this was just some guy who went 'let's ship it to all our customers!' or if this was a C-level 300 hours of meetings type of thing which concluded that spreading christmas ~~malware~~ cheer was the right move.

[-] adarza@lemmy.ca 35 points 6 months ago

this was downloaded and 'installed' by asus armory crate, which came from malware baked right into the bios of new and 'newish' asus motherboards (how to disable)

load more comments (1 replies)
[-] oo1@lemmings.world 58 points 6 months ago

"do not panic – your device is not compromised."

meme(always has been)

[-] zerofk@lemm.ee 23 points 6 months ago

There is nothing wrong with your device. Do not attempt to adjust the picture. We control the horizontal. We control the vertical.

[-] umbraroze@lemmy.world 19 points 6 months ago

...We control the treble, and all your bass belongs to us too.

/incredibly ancient joke

load more comments (1 replies)
load more comments (1 replies)
[-] reksas@sopuli.xyz 21 points 6 months ago

if someone not you installing crap you dont want isn't compromised then i dont what is

[-] Buffalox@lemmy.world 48 points 6 months ago* (last edited 6 months ago)

Why don't every vendor with an installed app make a similar banner?
It would be so festive, and I bet people would love it, to have 20 or 30 such occurrences every time you need to use your computer during holidays.
It would of course be optimal if each has an animation and a tune, that need to finish before you can escape.
Weird that only Asus had this brilliant idea? It's so awesome when you are not in control of what happens on your computer.
/s

If you want to take back control, Linux is your best option.

[-] TimeSquirrel@kbin.melroy.org 23 points 6 months ago

Oooh, make one of them a little purple animated gorilla, I'd like that too.

load more comments (2 replies)
load more comments (1 replies)
[-] Magnetic_dud@discuss.tchncs.de 39 points 6 months ago

The manager who approved this need to be fired. Programs need to ask permission to the user before installing, especially when they're not device drivers.

This is literal malware and there's also a chance that it might be exploited (example: a mitm Attack exchanges the file that armory crate is downloading)

This kind of Easter egg is not funny at all, developers must avoid undocumented time bombs. I still remember that day 15 years ago when I turned on my Wii and it said that the system files were corrupted. After hours of reverting a full nand backup via bootmii (and losing 2 years of game saves) it turned out that it was a funny April's fool by crediar, which put a fake system corruption message when you run his program on April 1st. Problem is that his program was a loader for the system menu so it was unavoidable if you didn't know that.

Like me, there must be someone paranoid that saw that black bar on the screen, saw a weird Christmas.exe running on their system, and starting wiping or restoring old images to "clean" that.

[-] thermal_shock@lemmy.world 38 points 6 months ago* (last edited 6 months ago)

everyone submit a help desk ticket to Asus asking wtf is going on

[-] Shimitar@feddit.it 33 points 6 months ago

Somebody should create a windows executable to be placed in the WPBT that silently install Linux on first windows boot....

[-] TonyTonyChopper@mander.xyz 29 points 6 months ago

the wreath has a memory leak

modern app design and its consequences

load more comments (1 replies)
[-] tabular@lemmy.world 22 points 6 months ago

An unsolicited Christmas card through a letterbox would have at least been less worrying.

[-] Mwa@lemm.ee 20 points 6 months ago* (last edited 6 months ago)

Thank god I was using Linux
Edit:Nvm its Armory crate shenanigans

[-] Nougat@fedia.io 24 points 6 months ago

LINUX LINUX LINUX LINUX LINUX LINUX LINUX LINUX LINUX LINUX LINUX LINUX LINUX LINUX LINUX LINUX LINUX LINUX LINUX LINUX LINUX LINUX LINUX

[-] melroy@kbin.melroy.org 21 points 6 months ago

GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux GNU/Linux..

load more comments (4 replies)
load more comments (2 replies)
load more comments (2 replies)
[-] 01189998819991197253@infosec.pub 16 points 6 months ago

How was this even approved for deployment?

[-] LutefiskPizza@fedia.io 16 points 6 months ago

Haha, how fortuitous for me that my new SDD arrived over the weekend and I used the opportunity to install Linux on my Asus laptop.

[-] Flashback956@feddit.nl 16 points 6 months ago* (last edited 6 months ago)

Another reason to not buy any Asus stuff.

[-] carp1@lemm.ee 15 points 6 months ago

awesome, merry christmas

[-] rem26_art@fedia.io 14 points 6 months ago

Why???? who thought this was a good idea?!?

[-] 4am@lemm.ee 14 points 6 months ago

Make no mistake, they will backpedal and apologize, but this was a flex. They want the public to know that their machines are fucking pwnt from top to bottom and they shouldn’t try any funny shit.

[-] tabular@lemmy.world 13 points 6 months ago

I find it difficult to choose a motherboard because they all look shady. aSUS should be criticized for creating a bad app and installing it without consent but I feel like this could have been any other motherboard manufacture.

load more comments (1 replies)
[-] Alph4d0g@discuss.tchncs.de 13 points 6 months ago

Windows is a choice. You made it. Congratulations.

[-] Emerald@lemmy.world 14 points 6 months ago

This doesn't have anything to do with Windows. This is ASUS's fault

load more comments (1 replies)
load more comments (2 replies)
load more comments
view more: next ›
this post was submitted on 24 Dec 2024
752 points (100.0% liked)

Technology

72764 readers
1373 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS