Live data from Hacker News

Dell shipping laptop with rogue self-signed root CA

np.reddit.com

71–80 of 109 posts

Re: Dell shipping laptop with rogue self-signed root CA

#71
post #67
post #10

Here's a test website from Kenn White: https://bogus.lessonslearned.org/

What does the test site do?

If you don't get a big + scary "Invalid Cert, unsafe!, unsafe!" warning - you have the dell CA installed and trusted...

Re: Dell shipping laptop with rogue self-signed root CA

#72
post #67
post #10

Here's a test website from Kenn White: https://bogus.lessonslearned.org/

What does the test site do?

It is signed by the eDellRoot certificate, if you visit the page and you don’t see any certificate warning, then your machine probably has the eDellRoot certificate installed.

Re: Dell shipping laptop with rogue self-signed root CA

#74

One should always do a clean install of Windows with a OEM disc when buy a new PC. You can avoid a lot of issues that way...

Or buy "Signature Edition" from Microsoft http://www.microsoftstore.com/store/msusa/en_US/cat/Signatur...

At this point, the price "advantage" for Windows PCs vs. a Mac is tenuous at best... especially since a lot of folks buy on some "30% off this week" deal with Dell/Lenovo/etc.

Re: Dell shipping laptop with rogue self-signed root CA

#75
post #67
post #10

Here's a test website from Kenn White: https://bogus.lessonslearned.org/

What does the test site do?

it's got a certificate signed by the bogus certificate authority that dell bundled. So if your browser accepts the certificate (eg shows a green https instead of preventing the page from loading and displaying a warning) then the CA is installed and trusted on your machine

Re: Dell shipping laptop with rogue self-signed root CA

#77
post #3
post #2

[1] suggests that this can be used for code signing, but not to MITM network requests, which makes it bad in a different way to superfish. [1] https://np.reddit.com/r/technology/comments/3twmfv/dell_ship...

Right, but the private key is also included(!), so anyone can now sign code that will be trusted by these computers. Edit: Confirmed can issue ssl certs. https://mobile.twitter.com/_xpn_/status/668745489823768576

Why in the world did Dell ship the private key?

Re: Dell shipping laptop with rogue self-signed root CA

#78

Karmic. Straight from Dell's website: Dell is serious about your privacy Worried about Superfish? Dell limits its pre-loaded software to a small number of high-value applications on all of our computers. Each application we pre-load undergoes security, privacy and usability testing to ensure that our customers experience the best possible computing performance, faster set-up and reduced privacy and security concerns.

Total horse shit. Family member bought a Dell not too long ago and it was filled to the brim with spyware.

Do you actually mean spyware, as in low-grade virus, or just preinstalled software? I'd be highly surprised if they bundled actual spyware with their machines.

Re: Dell shipping laptop with rogue self-signed root CA

#79
post #31

On Android I only buy and recommend Nexus devices because of crapware, privacy and security concerns. It might be a good time for Microsoft users to switch to that same strategy and only buy Microsoft devices, since the introduction of Microsoft's own laptop makes it possible. It's also pretty much the Apple model.

Why? Surface Book costs more than a Macbook. Windows laptops sell because they're cheap.

Re: Dell shipping laptop with rogue self-signed root CA

#80

Earlier quoted context omitted.

Or buy "Signature Edition" from Microsoft http://www.microsoftstore.com/store/msusa/en_US/cat/Signatur...

So buy it twice to get a good copy? Microsoft really needs to reel in the bad behaviour on the part of the OEMs.

The US government launched a massive anti-trust case against Microsoft to enable OEMs to do whatever they wanted.

It cost Microsoft many billions of dollars, almost had the company broken up, and put them under close Department of Justice supervision for a decade. I don't think Microsoft will risk anything like that again....

Post reply on HN