Dell shipping laptop with rogue self-signed root CA
np.reddit.com
Dell shipping laptop with rogue self-signed root CA
1–10 of 109 posts
Re: Dell shipping laptop with rogue self-signed root CA
#2[1] https://np.reddit.com/r/technology/comments/3twmfv/dell_ship...
Re: Dell shipping laptop with rogue self-signed root CA
#3[1] suggests that this can be used for code signing, but not to MITM network requests, which makes it bad in a different way to superfish. [1] https://np.reddit.com/r/technology/comments/3twmfv/dell_ship...
Edit: Confirmed can issue ssl certs. https://mobile.twitter.com/_xpn_/status/668745489823768576
Re: Dell shipping laptop with rogue self-signed root CA
#4Re: Dell shipping laptop with rogue self-signed root CA
#5Source: I worked for hardware vendor and wrote windows drivers.
Re: Dell shipping laptop with rogue self-signed root CA
#6Seems like a way to bypass signed drivers. Sending drivers to Microsoft for signing takes a few weeks and costs money. I bet this certificate was used on prototypes, but was not removed from final version for some reason. Source: I worked for hardware vendor and wrote windows drivers.
Re: Dell shipping laptop with rogue self-signed root CA
#7Seems like a way to bypass signed drivers. Sending drivers to Microsoft for signing takes a few weeks and costs money. I bet this certificate was used on prototypes, but was not removed from final version for some reason. Source: I worked for hardware vendor and wrote windows drivers.
I thought you could get a code signing cert from MS, but the WHQL qualification is what involves the latter phase?
Re: Dell shipping laptop with rogue self-signed root CA
#8Re: Dell shipping laptop with rogue self-signed root CA
#9[1] suggests that this can be used for code signing, but not to MITM network requests, which makes it bad in a different way to superfish. [1] https://np.reddit.com/r/technology/comments/3twmfv/dell_ship...