Earlier quoted context omitted.
No no, sorry. Signature edition is buying the computer itself, not rebuying the OS. They're computers from Dell/Toshiba/Acer/etc. sold directly by Microsoft without any garbageware. Saves you the hassle of having to do a clean install after you buy it.
Do you have a link that explains what this is? The previous one dumped me on some random Microsoft Store page.
Dell shipping laptop with rogue self-signed root CA
61–70 of 109 posts
Re: Dell shipping laptop with rogue self-signed root CA
#62Seems like a way to bypass signed drivers. Sending drivers to Microsoft for signing takes a few weeks and costs money. I bet this certificate was used on prototypes, but was not removed from final version for some reason. Source: I worked for hardware vendor and wrote windows drivers.
I have seen driver installers that just install their own CA. A particularly clever one generated a CA at install time, signed the driver, deleted the private key, then installed the driver, however this relied on internet access during install to timestamp the driver signature. I wonder if this works for kernel mode drivers?
Re: Dell shipping laptop with rogue self-signed root CA
#63> You have been linked to a read-only version of this subreddit. Please respect the community by not voting. Please do not vote or comment when you come from external subreddits.
wtf?
Re: Dell shipping laptop with rogue self-signed root CA
#64Earlier quoted context omitted.
But it would be a screw up in Dell's core activity. It's like Intel screwing up the design of the Xeon. I would be surprised if this didn't get approved by many people before going ahead.
At least on the consumer end, I'd say Dell's "core activity" is hardware, not software. This is more like Intel selling software that can screw up your computer: https://www.mcafee.com/
Re: Dell shipping laptop with rogue self-signed root CA
#65[1] suggests that this can be used for code signing, but not to MITM network requests, which makes it bad in a different way to superfish. [1] https://np.reddit.com/r/technology/comments/3twmfv/dell_ship...
Re: Dell shipping laptop with rogue self-signed root CA
#66Karmic. Straight from Dell's website: Dell is serious about your privacy Worried about Superfish? Dell limits its pre-loaded software to a small number of high-value applications on all of our computers. Each application we pre-load undergoes security, privacy and usability testing to ensure that our customers experience the best possible computing performance, faster set-up and reduced privacy and security concerns.
This raises an interesting paradox to me. How would the people writing the marketing copy for any product that was supposedly Superfish-resilient actually know that it was? Is the solution to simply not have marketing around such technical details? Is there a solution?
If you want a fun corporate PR check out Microsofts http://niewspierajhakera.pl/
This is a Polish anti piracy campaign equalling everyone who calls himself a Hacker to ISIS terrorist and pedophile :/ Thats right, they uploaded YT clips showing "hackers" in balaclavas collecting child porn. At the very same time Microsoft openly calls polish makers Hackers in another part of corporate portal.
Re: Dell shipping laptop with rogue self-signed root CA
#67Here's a test website from Kenn White: https://bogus.lessonslearned.org/
Re: Dell shipping laptop with rogue self-signed root CA
#68On Android I only buy and recommend Nexus devices because of crapware, privacy and security concerns. It might be a good time for Microsoft users to switch to that same strategy and only buy Microsoft devices, since the introduction of Microsoft's own laptop makes it possible. It's also pretty much the Apple model.
Microsoft sells laptops from different manufacturers with Signature Edition. Those laptops don't have any junk.
I bought a Signature Edition Thinkpad Yoga S1 from Microsoft and it didn't have any junk on it, except in the registry. I think all they do is open the machine, uninstall all the non-Microsoft stuff, then ship the machine. A clean install wouldn't have registry keys for Evernote (for example).
I think I would only buy a Microsoft Surface machine at this point. The hardware is very good and they aren't junked up.
Re: Dell shipping laptop with rogue self-signed root CA
#69Off topic: I dont reddit that much, so this is a first time I see this banner (specifically crafted to not be copyable!) > You have been linked to a read-only version of this subreddit. Please respect the community by not voting. Please do not vote or comment when you come from external subreddits. wtf?
Re: Dell shipping laptop with rogue self-signed root CA
#70I love the Dell response: "We have top men working on it."
Can you link to where you see this? I don't see that quote in TFA.
They are being asked about this over-and-over again, and they just spit back the same nothing response every time that is essentially what the person you replied to said.