Live data from Hacker News

Dell shipping laptop with rogue self-signed root CA

np.reddit.com

91–100 of 109 posts

Re: Dell shipping laptop with rogue self-signed root CA

#92
post #31

On Android I only buy and recommend Nexus devices because of crapware, privacy and security concerns. It might be a good time for Microsoft users to switch to that same strategy and only buy Microsoft devices, since the introduction of Microsoft's own laptop makes it possible. It's also pretty much the Apple model.

An interesting thing I realized on Android while doing some development was that if you install a custom root cert, Android actually persists a notification that says something along the lines of "other people may be able to intercept your communication". Noticed this while I was installing the MITM cert for CharlesProxy.

Which is really annoying if you actually want to import a different CA (like CAcert.org).

Re: Dell shipping laptop with rogue self-signed root CA

#93
post #58

Take a look at the screenshot of the certificate store. Why are expired certs from 1999 in there? What's that "NO LIABILITY ACCEPTED" cert? Do you really have the private key for the self-signed cert? This is worth a vulnerability report to US-CERT, and more publicity.

Those weird trusted root CA's are preloaded by Microsoft https://support.microsoft.com/en-us/kb/293781

Re: Dell shipping laptop with rogue self-signed root CA

#94

I love the Dell response: "We have top men working on it."

Can you link to where you see this? I don't see that quote in TFA.

I think the mods changed the link. The original was a blog post, and one of the comments was from Dell and essentially said "We are Dell and we like security. Our experts are furiously working on security. We'll let you know what they come up with."

Re: Dell shipping laptop with rogue self-signed root CA

#95
post #5

Seems like a way to bypass signed drivers. Sending drivers to Microsoft for signing takes a few weeks and costs money. I bet this certificate was used on prototypes, but was not removed from final version for some reason. Source: I worked for hardware vendor and wrote windows drivers.

That doesn't explain why the private key was on the prototype itself.

Re: Dell shipping laptop with rogue self-signed root CA

#96
post #77
post #3

Earlier quoted context omitted.

Right, but the private key is also included(!), so anyone can now sign code that will be trusted by these computers. Edit: Confirmed can issue ssl certs. https://mobile.twitter.com/_xpn_/status/668745489823768576

Why in the world did Dell ship the private key?

So that a program could use this Cert + Key to create arbitrary signed certs for google.com, facebook.com, etc. etc.

This is what the Superfish software did.

Re: Dell shipping laptop with rogue self-signed root CA

#97
post #80

Earlier quoted context omitted.

The US government launched a massive anti-trust case against Microsoft to enable OEMs to do whatever they wanted. It cost Microsoft many billions of dollars, almost had the company broken up, and put them under close Department of Justice supervision for a decade. I don't think Microsoft will risk anything like that again....

Microsoft didn't get sued for trying to make installing Windows easier. It got sued for making changes in Windows designed to damage competitors (specifically Netscape, Sun, Borland, and Apple) and publicly and repeatedly lying about it.

The heart of the case was whether OEMs could install Netscape and/or remove IE. One direct result was that Microsoft could not insist on its preferred installation of Windows.

Microsoft was also prevented from charging the major OEMs different prices, which was its main way of rewarding OEMs for doing installations the way Microsoft wanted.

Re: Dell shipping laptop with rogue self-signed root CA

#98
post #97

Earlier quoted context omitted.

Microsoft didn't get sued for trying to make installing Windows easier. It got sued for making changes in Windows designed to damage competitors (specifically Netscape, Sun, Borland, and Apple) and publicly and repeatedly lying about it.

The heart of the case was whether OEMs could install Netscape and/or remove IE. One direct result was that Microsoft could not insist on its preferred installation of Windows. Microsoft was also prevented from charging the major OEMs different prices, which was its main way of rewarding OEMs for doing installations the way Microsoft wanted.

This is true -- but again Microsoft got caught lying about how IE's functionality was "intrinsic" to Windows (which was why it prevented IE from being uninstalled). It was also forcing PC manufacturers to pay a royalty for every PC sold, whether or not it was bundled with DOS or Windows (which damaged rivals like Digital Research -- the company Microsoft essentially stole DOS from, but that's another story).

Re: Dell shipping laptop with rogue self-signed root CA

#99
post #63

Off topic: I dont reddit that much, so this is a first time I see this banner (specifically crafted to not be copyable!) > You have been linked to a read-only version of this subreddit. Please respect the community by not voting. Please do not vote or comment when you come from external subreddits. wtf?

When you add the np subdomain prefix to a reddit domain, it links to a non-participation version of the page. The idea is that it helps to reduce "brigading", as in if a thread is linked to by an external party or another subreddit, the thread is not so easily derailed from its original context and audience. Of course if you actually want to participate in the thread, its not difficult to simply remove the prefix. Bu…

Thank you for the explanation. It does look very tinfoil hat for the outsider with no knowledge of what it is.
Post reply on HN