Seems like a way to bypass signed drivers. Sending drivers to Microsoft for signing takes a few weeks and costs money. I bet this certificate was used on prototypes, but was not removed from final version for some reason. Source: I worked for hardware vendor and wrote windows drivers.
Dell shipping laptop with rogue self-signed root CA
51–60 of 109 posts
Re: Dell shipping laptop with rogue self-signed root CA
#52This should be the NSA's job, keeping us safe from all the corporate and foreign government cyber espionage that is completely out of control. In reality they don't give a shit because they like to free ride on top of all the other backdoors as well as the ones they create.
The NSA's job does entail keeping government communications secret and secure. So whole buildings of people do "give a shit" about stuff like this.
Re: Dell shipping laptop with rogue self-signed root CA
#53Earlier quoted context omitted.
> This raises an interesting paradox to me. How would the people writing the marketing copy for any product that was supposedly Superfish-resilient actually know that it was? A big difference is that Dell's inclusion of the private key appears to be a (major) screwup by someone with technical responsibility[0], whereas Superfish was downright intentional and involved people all over the company. In that light, this d…
But it would be a screw up in Dell's core activity. It's like Intel screwing up the design of the Xeon. I would be surprised if this didn't get approved by many people before going ahead.
Re: Dell shipping laptop with rogue self-signed root CA
#54Earlier quoted context omitted.
I would change that last part to say "means nothing when you have shady OS makers building this mechanism." I mean, come on, Microsoft, what were you thinking? Vendors gonna vend, so you had to know how this "feature" was going to be used.
Microsoft created the feature so you'd actually have driver support when doing the reset. I'm sure we all love resetting a touch screen only machine to find out it has no touch support for the install.
Re: Dell shipping laptop with rogue self-signed root CA
#55Earlier quoted context omitted.
> This raises an interesting paradox to me. How would the people writing the marketing copy for any product that was supposedly Superfish-resilient actually know that it was? A big difference is that Dell's inclusion of the private key appears to be a (major) screwup by someone with technical responsibility[0], whereas Superfish was downright intentional and involved people all over the company. In that light, this d…
But it would be a screw up in Dell's core activity. It's like Intel screwing up the design of the Xeon. I would be surprised if this didn't get approved by many people before going ahead.
Re: Dell shipping laptop with rogue self-signed root CA
#56Earlier quoted context omitted.
So buy it twice to get a good copy? Microsoft really needs to reel in the bad behaviour on the part of the OEMs.
No no, sorry. Signature edition is buying the computer itself, not rebuying the OS. They're computers from Dell/Toshiba/Acer/etc. sold directly by Microsoft without any garbageware. Saves you the hassle of having to do a clean install after you buy it.
Re: Dell shipping laptop with rogue self-signed root CA
#57Karmic. Straight from Dell's website: Dell is serious about your privacy Worried about Superfish? Dell limits its pre-loaded software to a small number of high-value applications on all of our computers. Each application we pre-load undergoes security, privacy and usability testing to ensure that our customers experience the best possible computing performance, faster set-up and reduced privacy and security concerns.
This raises an interesting paradox to me. How would the people writing the marketing copy for any product that was supposedly Superfish-resilient actually know that it was? Is the solution to simply not have marketing around such technical details? Is there a solution?
They just write whatever sells.
Re: Dell shipping laptop with rogue self-signed root CA
#58This is worth a vulnerability report to US-CERT, and more publicity.
Re: Dell shipping laptop with rogue self-signed root CA
#59I love the Dell response: "We have top men working on it."
Re: Dell shipping laptop with rogue self-signed root CA
#60Earlier quoted context omitted.
Microsoft created the feature so you'd actually have driver support when doing the reset. I'm sure we all love resetting a touch screen only machine to find out it has no touch support for the install.
They could have just put the drivers on the CD like every linux distro ever.