Live data from Hacker News

Dell shipping laptop with rogue self-signed root CA

np.reddit.com

51–60 of 109 posts

Re: Dell shipping laptop with rogue self-signed root CA

#51
post #5

Seems like a way to bypass signed drivers. Sending drivers to Microsoft for signing takes a few weeks and costs money. I bet this certificate was used on prototypes, but was not removed from final version for some reason. Source: I worked for hardware vendor and wrote windows drivers.

Can you actually do that? I was under the impression that the kernel driver root certs aren't under user control, and you basically have to boot your Windows in debug mode to run an unsigned driver. Surely people would just self-sign instead if that was possible.

Re: Dell shipping laptop with rogue self-signed root CA

#52
post #12

This should be the NSA's job, keeping us safe from all the corporate and foreign government cyber espionage that is completely out of control. In reality they don't give a shit because they like to free ride on top of all the other backdoors as well as the ones they create.

The NSA's job does entail keeping government communications secret and secure. So whole buildings of people do "give a shit" about stuff like this.

Since Dell holds a ton of government contracts and a good amount of government computers are Dell, you can guarantee they most DEFINITELY "give a shit" about this.

Re: Dell shipping laptop with rogue self-signed root CA

#53
post #43

Earlier quoted context omitted.

> This raises an interesting paradox to me. How would the people writing the marketing copy for any product that was supposedly Superfish-resilient actually know that it was? A big difference is that Dell's inclusion of the private key appears to be a (major) screwup by someone with technical responsibility[0], whereas Superfish was downright intentional and involved people all over the company. In that light, this d…

But it would be a screw up in Dell's core activity. It's like Intel screwing up the design of the Xeon. I would be surprised if this didn't get approved by many people before going ahead.

At least on the consumer end, I'd say Dell's "core activity" is hardware, not software. This is more like Intel selling software that can screw up your computer: https://www.mcafee.com/

Re: Dell shipping laptop with rogue self-signed root CA

#54
post #27

Earlier quoted context omitted.

I would change that last part to say "means nothing when you have shady OS makers building this mechanism." I mean, come on, Microsoft, what were you thinking? Vendors gonna vend, so you had to know how this "feature" was going to be used.

Microsoft created the feature so you'd actually have driver support when doing the reset. I'm sure we all love resetting a touch screen only machine to find out it has no touch support for the install.

Perhaps this would encourage vendors to actually follow standards for their input devices so they didn't require custom drivers. Win-win!

Re: Dell shipping laptop with rogue self-signed root CA

#55
post #43

Earlier quoted context omitted.

> This raises an interesting paradox to me. How would the people writing the marketing copy for any product that was supposedly Superfish-resilient actually know that it was? A big difference is that Dell's inclusion of the private key appears to be a (major) screwup by someone with technical responsibility[0], whereas Superfish was downright intentional and involved people all over the company. In that light, this d…

But it would be a screw up in Dell's core activity. It's like Intel screwing up the design of the Xeon. I would be surprised if this didn't get approved by many people before going ahead.

Many hardware companies regard software as an afterthought, not a core activity; it's often outsourced.

Re: Dell shipping laptop with rogue self-signed root CA

#56

Earlier quoted context omitted.

So buy it twice to get a good copy? Microsoft really needs to reel in the bad behaviour on the part of the OEMs.

No no, sorry. Signature edition is buying the computer itself, not rebuying the OS. They're computers from Dell/Toshiba/Acer/etc. sold directly by Microsoft without any garbageware. Saves you the hassle of having to do a clean install after you buy it.

Do you have a link that explains what this is? The previous one dumped me on some random Microsoft Store page.

Re: Dell shipping laptop with rogue self-signed root CA

#57
post #40

Karmic. Straight from Dell's website: Dell is serious about your privacy Worried about Superfish? Dell limits its pre-loaded software to a small number of high-value applications on all of our computers. Each application we pre-load undergoes security, privacy and usability testing to ensure that our customers experience the best possible computing performance, faster set-up and reduced privacy and security concerns.

This raises an interesting paradox to me. How would the people writing the marketing copy for any product that was supposedly Superfish-resilient actually know that it was? Is the solution to simply not have marketing around such technical details? Is there a solution?

>How would the people writing the marketing copy for any product that was supposedly Superfish-resilient actually know that it was?

They just write whatever sells.

Re: Dell shipping laptop with rogue self-signed root CA

#58
Take a look at the screenshot of the certificate store. Why are expired certs from 1999 in there? What's that "NO LIABILITY ACCEPTED" cert? Do you really have the private key for the self-signed cert?

This is worth a vulnerability report to US-CERT, and more publicity.

Re: Dell shipping laptop with rogue self-signed root CA

#60

Earlier quoted context omitted.

Microsoft created the feature so you'd actually have driver support when doing the reset. I'm sure we all love resetting a touch screen only machine to find out it has no touch support for the install.

They could have just put the drivers on the CD like every linux distro ever.

You mean the CD recovery image disk which would ostensibly have all the same bloat/spyware as the PC itself?
Post reply on HN