On Android I only buy and recommend Nexus devices because of crapware, privacy and security concerns. It might be a good time for Microsoft users to switch to that same strategy and only buy Microsoft devices, since the introduction of Microsoft's own laptop makes it possible. It's also pretty much the Apple model.
Dell shipping laptop with rogue self-signed root CA
41–50 of 109 posts
Re: Dell shipping laptop with rogue self-signed root CA
#42Karmic. Straight from Dell's website: Dell is serious about your privacy Worried about Superfish? Dell limits its pre-loaded software to a small number of high-value applications on all of our computers. Each application we pre-load undergoes security, privacy and usability testing to ensure that our customers experience the best possible computing performance, faster set-up and reduced privacy and security concerns.
This raises an interesting paradox to me. How would the people writing the marketing copy for any product that was supposedly Superfish-resilient actually know that it was? Is the solution to simply not have marketing around such technical details? Is there a solution?
A big difference is that Dell's inclusion of the private key appears to be a (major) screwup by someone with technical responsibility[0], whereas Superfish was downright intentional and involved people all over the company.
In that light, this doesn't really appear to be a paradox - no company should ever market themselves as being immune to mistakes and/or breaches. But it's pretty straightforward to live up to promises that you won't intentionally compromise all security whatsoever just to make a few ad dollars (which is what Lenovo did).
[0] As far as I can tell, there's no evidence that Dell benefits in any way from shipping the private key, so I'm going to invoke Hanlon's razor until we discover otherwise: https://en.wikipedia.org/wiki/Hanlon%27s_razor
Re: Dell shipping laptop with rogue self-signed root CA
#43Earlier quoted context omitted.
This raises an interesting paradox to me. How would the people writing the marketing copy for any product that was supposedly Superfish-resilient actually know that it was? Is the solution to simply not have marketing around such technical details? Is there a solution?
> This raises an interesting paradox to me. How would the people writing the marketing copy for any product that was supposedly Superfish-resilient actually know that it was? A big difference is that Dell's inclusion of the private key appears to be a (major) screwup by someone with technical responsibility[0], whereas Superfish was downright intentional and involved people all over the company. In that light, this d…
Re: Dell shipping laptop with rogue self-signed root CA
#44Earlier quoted context omitted.
What about installing an intermediate linux system? Like 1. start with window pre-installed 2. install any linux distro, fully overwriting the OEM 3. re-install windows, from microsoft I'd say just stop at step 2 ;) but I can understand that not everybody can do this (eg: work computer) but want a clean OS. will this method work to remove such bloatware?
This won't work because the firmware will write a file to your hard drive with the bloatware. It's scary that firmware will modify my filesystem - lots of damage could happen here. Also, instead of step 2, it would make more sense to boot linux on a usb stick and use dd to erase the hard drive -- this is more complete than installing another OS... but still useless if the firmware is working against you.
Re: Dell shipping laptop with rogue self-signed root CA
#45On Android I only buy and recommend Nexus devices because of crapware, privacy and security concerns. It might be a good time for Microsoft users to switch to that same strategy and only buy Microsoft devices, since the introduction of Microsoft's own laptop makes it possible. It's also pretty much the Apple model.
Buying devices only from Google or Microsoft is a little better as it might remove one layer of involuntary data sharing but it would still be better wiping off Android and replacing it with something else that is more privacy oriented...
Re: Dell shipping laptop with rogue self-signed root CA
#46Earlier quoted context omitted.
> This raises an interesting paradox to me. How would the people writing the marketing copy for any product that was supposedly Superfish-resilient actually know that it was? A big difference is that Dell's inclusion of the private key appears to be a (major) screwup by someone with technical responsibility[0], whereas Superfish was downright intentional and involved people all over the company. In that light, this d…
But it would be a screw up in Dell's core activity. It's like Intel screwing up the design of the Xeon. I would be surprised if this didn't get approved by many people before going ahead.
I'm not really sure I'd say that this is comparable to Intel screwing up the design of the Xeon.
But either way, there's a big difference between "we made a serious technical error, and nobody at the company caught this" and "we intentionally compromised our entire product because advertisers were willing to pay us, and nobody at the company stopped this".
Re: Dell shipping laptop with rogue self-signed root CA
#47Earlier quoted context omitted.
> This raises an interesting paradox to me. How would the people writing the marketing copy for any product that was supposedly Superfish-resilient actually know that it was? A big difference is that Dell's inclusion of the private key appears to be a (major) screwup by someone with technical responsibility[0], whereas Superfish was downright intentional and involved people all over the company. In that light, this d…
But it would be a screw up in Dell's core activity. It's like Intel screwing up the design of the Xeon. I would be surprised if this didn't get approved by many people before going ahead.
Re: Dell shipping laptop with rogue self-signed root CA
#48Earlier quoted context omitted.
Or buy "Signature Edition" from Microsoft http://www.microsoftstore.com/store/msusa/en_US/cat/Signatur...
So buy it twice to get a good copy? Microsoft really needs to reel in the bad behaviour on the part of the OEMs.
Re: Dell shipping laptop with rogue self-signed root CA
#49Earlier quoted context omitted.
I would change that last part to say "means nothing when you have shady OS makers building this mechanism." I mean, come on, Microsoft, what were you thinking? Vendors gonna vend, so you had to know how this "feature" was going to be used.
Microsoft created the feature so you'd actually have driver support when doing the reset. I'm sure we all love resetting a touch screen only machine to find out it has no touch support for the install.