Live data from Hacker News

Dell shipping laptop with rogue self-signed root CA

np.reddit.com

31–40 of 109 posts

Re: Dell shipping laptop with rogue self-signed root CA

#31
On Android I only buy and recommend Nexus devices because of crapware, privacy and security concerns. It might be a good time for Microsoft users to switch to that same strategy and only buy Microsoft devices, since the introduction of Microsoft's own laptop makes it possible. It's also pretty much the Apple model.

Re: Dell shipping laptop with rogue self-signed root CA

#32

One should always do a clean install of Windows with a OEM disc when buy a new PC. You can avoid a lot of issues that way...

Yeah, so that may not be possible.

I have a HP laptop with a Windows 7 license key under the battery and I can only install Windows 7 from HP recovery disks.

Of course, I opted to say "fuck you" and torrented a Win7 installation disk and activator, but that is not an option most of the time.

Re: Dell shipping laptop with rogue self-signed root CA

#33

Karmic. Straight from Dell's website: Dell is serious about your privacy Worried about Superfish? Dell limits its pre-loaded software to a small number of high-value applications on all of our computers. Each application we pre-load undergoes security, privacy and usability testing to ensure that our customers experience the best possible computing performance, faster set-up and reduced privacy and security concerns.

In case they think it wise to remove that blurb (it's on various product pages):

https://web.archive.org/web/20151123183352/http://www.dell.c...

Re: Dell shipping laptop with rogue self-signed root CA

#34
post #27

Earlier quoted context omitted.

Lenovo uses Microsoft Windows Platform Binary Table to install bloatware, which gets around any kind of clean install/reset. Clean install for Windows means nothing when you have shady vendors utilizing this mechanism.

I would change that last part to say "means nothing when you have shady OS makers building this mechanism." I mean, come on, Microsoft, what were you thinking? Vendors gonna vend, so you had to know how this "feature" was going to be used.

Microsoft created the feature so you'd actually have driver support when doing the reset. I'm sure we all love resetting a touch screen only machine to find out it has no touch support for the install.

Re: Dell shipping laptop with rogue self-signed root CA

#35
post #31

On Android I only buy and recommend Nexus devices because of crapware, privacy and security concerns. It might be a good time for Microsoft users to switch to that same strategy and only buy Microsoft devices, since the introduction of Microsoft's own laptop makes it possible. It's also pretty much the Apple model.

Buying devices only from Google or Microsoft is a little better as it might remove one layer of involuntary data sharing but it would still be better wiping off Android and replacing it with something else that is more privacy oriented...

Re: Dell shipping laptop with rogue self-signed root CA

#36
post #31

On Android I only buy and recommend Nexus devices because of crapware, privacy and security concerns. It might be a good time for Microsoft users to switch to that same strategy and only buy Microsoft devices, since the introduction of Microsoft's own laptop makes it possible. It's also pretty much the Apple model.

Microsoft sells laptops from different manufacturers with Signature Edition. Those laptops don't have any junk.

Re: Dell shipping laptop with rogue self-signed root CA

#37

Karmic. Straight from Dell's website: Dell is serious about your privacy Worried about Superfish? Dell limits its pre-loaded software to a small number of high-value applications on all of our computers. Each application we pre-load undergoes security, privacy and usability testing to ensure that our customers experience the best possible computing performance, faster set-up and reduced privacy and security concerns.

Total horse shit. Family member bought a Dell not too long ago and it was filled to the brim with spyware.

Re: Dell shipping laptop with rogue self-signed root CA

#38
post #31

On Android I only buy and recommend Nexus devices because of crapware, privacy and security concerns. It might be a good time for Microsoft users to switch to that same strategy and only buy Microsoft devices, since the introduction of Microsoft's own laptop makes it possible. It's also pretty much the Apple model.

All computers sold via the Microsoft Store are "Signature Edition" devices, sort of like the old "Google Play Edition" program: https://www.microsoftstore.com/store/msusa/en_US/cat/Signatu...

For example, the XPS 15: https://www.microsoftstore.com/store/msusa/en_US/pdp/Dell-XP...

Re: Dell shipping laptop with rogue self-signed root CA

#39
post #36
post #31

On Android I only buy and recommend Nexus devices because of crapware, privacy and security concerns. It might be a good time for Microsoft users to switch to that same strategy and only buy Microsoft devices, since the introduction of Microsoft's own laptop makes it possible. It's also pretty much the Apple model.

Microsoft sells laptops from different manufacturers with Signature Edition. Those laptops don't have any junk.

do they remain junk-free when you install manufacturer software updates? Was wondering if manufacturers are mandated to keep the signature laptops clean or if the first time you install your "control center / driver center" update it will automatically pull in things you'd rather not

Re: Dell shipping laptop with rogue self-signed root CA

#40

Karmic. Straight from Dell's website: Dell is serious about your privacy Worried about Superfish? Dell limits its pre-loaded software to a small number of high-value applications on all of our computers. Each application we pre-load undergoes security, privacy and usability testing to ensure that our customers experience the best possible computing performance, faster set-up and reduced privacy and security concerns.

This raises an interesting paradox to me. How would the people writing the marketing copy for any product that was supposedly Superfish-resilient actually know that it was?

Is the solution to simply not have marketing around such technical details? Is there a solution?

Post reply on HN