News: 1603978909

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Lenovo to slap ThinkShield security standard for laptop line-up on its Motorola mobiles

(2020/10/29)


Motorola will push [1]ThinkShield onto the business end of its smartphone portfolio, as an extension of the security and management programme on Lenovo's laptop and desktop line.

ThinkShield for mobile devices consists of four components, with the first being a "clean OS". In practice, this means Motorola will avoid loading up devices with unnecessary non-stock software, from additional bloatware to UI overlays. This element feels somewhat redundant given that Motorola has historically shipped devices with a near-untouched Android experience, in stark contrast to rival vendors like Samsung and Huawei.

The second pillar is the vague "secure by design." Here, Moto promises to build upon Android's existing security features with additional hardware and software-level components. These include a "fuse" that breaks when the phone's bootloader is unlocked, signifying the phone has been tampered with, as well as unspecified AI-powered protections against malware and phishing.

The next tier focuses on device enrolment and management, and replicates much of the spec of the [2]Android Enterprise Recommended Program – such as the requirement for contactless device enrolment and deployment. The Lenovo mobile unit also mentioned partnerships and certifications with third-party device management vendors, as well as a dedicated enterprise support service.

Finally, Motorola said it would focus on supply-chain security. The last component promises that the smartphone-maker will ensure all third-party suppliers meet its own security standards. Moto said it will also ensure heightened levels of security when provisioning devices at its own factory, and that staff have a dedicated incident response team to address suspected breaches.

Motorola plans to introduce support for ThinkShield in the coming months across its device portfolio, with the standard featuring on all upcoming phones. The Reg has asked about pricing, which presumably is based on SLAs/deployment, and will update when we hear back.

Lenovo [3]acquired Motorola Mobility from Google in 2014 for $2.91bn . The Chinese PC maker opted to preserve the Motorola brand, while pursuing aspirations in the mobile sphere with its Legion gaming lineup. The adoption of ThinkShield, with a logo hinting towards the iconic ThinkPad "nipple" is therefore indicative of some convergence between the two brands.

More substantially, it shows Motorola is thinking more closely about the enterprise market, which has traditionally been one of its strongest segments. Since the decline of BlackBerry as a force, this area has largely coalesced between two players, Apple and Samsung, which have invested heavily in device management and security in an attempt to court the sizeable corporate pound.

Still, there's plenty of room for growth, and Google has attempted to cultivate this segment through the Android Enterprise Recommended Program. This optional scheme includes vendors like Motorola and [4]Nokia , and establishes a baseline for device support, as well as a minimum support lifespan. ®

Get our [5]Tech Resources



[1] https://blog.motorola.com/2020/10/28/motorola-introduces-thinkshield-for-mobile-focused-on-corporate-customers/

[2] https://www.android.com/intl/en_uk/enterprise/recommended/

[3] https://www.theregister.com/2014/01/29/google_sells_motorola_to_lenovo_for_291bn_but_keeps_the_patents/

[4] https://www.theregister.com/2019/03/05/nokias_secret_being_boring/

[5] https://whitepapers.theregister.com/

The second pillar

Mike 137

" .. include a "fuse" that breaks when the phone's bootloader is unlocked, signifying the phone has been tampered ... "

So no legitimate repurposing possible? Depends on what the effect is of the "fuse" breaking - bricking maybe?

It would be great to have such features as options, having them forced on us seems rather excessively paternalistic. Almost every vendor or provider of IT now seems to think they must "secure" us forcibly whether we want to be secure or not.

Call me a skeptic but...

Anonymous Coward

My 6 year old Motorola already has a full-screen warning on boot-up if the bootloader has been unlocked.

And as the author has stated Motorola's already have very little if any bloat.

Also, Lenovo doesn't have a very good track record when it comes to them installing extra crap on their PC line of devices:

https://en.wikipedia.org/wiki/Lenovo#Controversies

I am willing to bet that in the near future we will be reading an article on this very site about how ThinkShield could lead to a complete compromise of the device.

Adding more complexity to any security model is never a good idea, KISS.

"I am ready to meet my Maker. Whether my Maker is prepared for the
great ordeal of meeting me is another matter."
-- Winston Churchill