Live data from Hacker News

Dell shipping laptop with rogue self-signed root CA

np.reddit.com

101–109 of 109 posts

Re: Dell shipping laptop with rogue self-signed root CA

#101
post #97

Earlier quoted context omitted.

The heart of the case was whether OEMs could install Netscape and/or remove IE. One direct result was that Microsoft could not insist on its preferred installation of Windows. Microsoft was also prevented from charging the major OEMs different prices, which was its main way of rewarding OEMs for doing installations the way Microsoft wanted.

This is true -- but again Microsoft got caught lying about how IE's functionality was "intrinsic" to Windows (which was why it prevented IE from being uninstalled). It was also forcing PC manufacturers to pay a royalty for every PC sold, whether or not it was bundled with DOS or Windows (which damaged rivals like Digital Research -- the company Microsoft essentially stole DOS from, but that's another story).

> how IE's functionality was "intrinsic" to Windows

Microsoft had been forced to sign a consent decree in 1995, which prevented it from tying new products to the OS but specifically allowed it to add new features to the OS. It therefore didn't have much choice about its arguments, though (like every other OS supplier) it obviously wanted to include a browser. Equally obviously, delivering a free browser as part of the OS was good for consumers, which is why Microsoft won the browser bundling case on appeal.

Microsoft had also componentized the browser so that different functions could be used by other programs, which to some extent, did make it part of the OS. (Much of the anti-trust case argument on that topic was phenomenally stupid.)

>It was also forcing PC manufacturers to pay a royalty for every PC sold, whether or not it was bundled with DOS or Windows

Don't think so. That was a deal offered to some OEMs, but as far as I know, it was never forced on anybody. In any case, the US Justice Department banned the idea in 1994. I tend to think 21+ years is a bit of long time to hold a grudge about something that was killed before it took off.

> Digital Research -- the company Microsoft essentially stole DOS from, but that's another story

Well, DR screwed up massively by refusing to sign a deal with IBM, then by charging too much for DR DOS, and then Apple screwed it in a court case over the UI in DR GEM. Either way, DR was dead long before the Microsoft anti-trust suit.

Re: Dell shipping laptop with rogue self-signed root CA

#102

I love the Dell response: "We have top men working on it."

Whenever I see an announcement to that effect, I'm reminded of this classic The Far Side cartoon: https://www.pinterest.com/pin/509399407824121060/

Alas, no new ones for over 20 years.

Re: Dell shipping laptop with rogue self-signed root CA

#103

I have a Dell M3800 that was purchased in March and has this cert. I am not well versed in this area. What do I do? Can I just delete it from the "Certificates" snap-in in MMC? (And should I?)

I'm replying to my own comment, because I can no longer edit it. This is a response that I received from reddit [0]. I haven't attempted it yet, but I wanted to include it here for completeness (and opinions):

> You can safely delete it from both the root and personal certificate stores. You will also need to remove the eDell plugin entirely otherwise the certificate will simply be reinstalled. If you have "Dell Foundation Services" listed in your programs you can uninstall it, otherwise you'll need to look for "Dell.Foundation.Agent.Plugins.eDell.dll" and delete it.

[0] https://www.reddit.com/r/tech/comments/3tzwuv/dell_does_a_su...

Re: Dell shipping laptop with rogue self-signed root CA

#104

One thing to note is, if you have your own Windows disks (some organizations might have) or if you use Linux this might not really matter to you. I wish laptops and desktops were sold without Operating Systems by the major companies, outside of server space.

There are quite a few low end laptops available in India without any pre-installed OS. Most people who buy these end up using some pirated copy of windows which is either left unpatched and vulnerable or it comes with some form of malware already installed. It hasn't been great for security or privacy sadly. No one I know uses linux on them or forks out any money for a Windows license which they deem to be too costly.

Re: Dell shipping laptop with rogue self-signed root CA

#106

I love the Dell response: "We have top men working on it."

The response I see is better: http://en.community.dell.com/dell-blogs/direct2dell/b/direct...

> We have posted instructions to permanently remove the certificate from your system here. We will also push a software update starting on November 24 that will check for the certificate, and if detected remove it. Commercial customers who reimaged their systems without Dell Foundation Services are not affected by this issue. Additionally, the certificate will be removed from all Dell systems moving forward.

> Your trust is important to us and we are actively working to address this issue. We thank customers such as Hanno Böck, Joe Nord and Kevin Hicks, aka rotorcowboy, who brought this to our attention. If you ever find a potential security vulnerability in any Dell product or software, we encourage you to visit this site to contact us immediately.

Re: Dell shipping laptop with rogue self-signed root CA

#107

I have a Dell M3800 that was purchased in March and has this cert. I am not well versed in this area. What do I do? Can I just delete it from the "Certificates" snap-in in MMC? (And should I?)

I'm replying to my own comment, because I can no longer edit it. This is a response that I received from reddit [0]. I haven't attempted it yet, but I wanted to include it here for completeness (and opinions): > You can safely delete it from both the root and personal certificate stores. You will also need to remove the eDell plugin entirely otherwise the certificate will simply be reinstalled. If you have "Dell Foun…

Here's the removal process from dell (PDF): https://dellupdater.dell.com/Downloads/APP009/eDellRootCerti...

Re: Dell shipping laptop with rogue self-signed root CA

#108

Earlier quoted context omitted.

This is true -- but again Microsoft got caught lying about how IE's functionality was "intrinsic" to Windows (which was why it prevented IE from being uninstalled). It was also forcing PC manufacturers to pay a royalty for every PC sold, whether or not it was bundled with DOS or Windows (which damaged rivals like Digital Research -- the company Microsoft essentially stole DOS from, but that's another story).

> how IE's functionality was "intrinsic" to Windows Microsoft had been forced to sign a consent decree in 1995, which prevented it from tying new products to the OS but specifically allowed it to add new features to the OS. It therefore didn't have much choice about its arguments, though (like every other OS supplier) it obviously wanted to include a browser. Equally obviously, delivering a free browser as part of th…

> "it was never forced on anybody"

Depends on what you mean by "forced", right? If a PC manufacturer's choice is between not selling PCs with Windows pre-installed and having to pay a per-PC license for Windows whether Windows is installed or not, then effectively it's forced. And this was likely in play for years, but covered by commercial in confidence.

> DR screwed up massively by refusing to sign a deal with IBM

Sure but that's a different issue entirely.

As a result of the litigation over 86-DOS/QDOS (which MS licensed from Seattle Computer Products) Seattle Computer Products, DR-DOS, IBM, and Microsoft ended up with the right to ship DOS. Microsoft acquired SCP's license for chump change via a dubious legal maneuver whereby it was forced to sell its license to MS rather than to anyone else for whatever they wanted to pay (I forget the detail, it's documented in one of the Gates biographies). DR and IBM continued to sell technically superior versions of DOS, but IBM's was bundled with IBM-branded hardware and DR was crippled by Microsoft's licensing contracts which became particularly effective once Windows 3.x came out.

> 21+ years is a bit of long time to hold a grudge

This is only the tip of the iceberg of things MS's anti-competitive behaviors. Probably its most pernicious behavior was "dumping" on rivals (cross-subsidizing products such as Access until rivals went out of business) and actively sabotaging third party software (e.g. -- allegedly -- deliberately breaking Lotus 1-2-3 on DOS 2.x and -- well-documented -- breaking Borland compilers in the Windows 95 betas (which might well have continued into the release version had it not been caught red-handed).

Re: Dell shipping laptop with rogue self-signed root CA

#109
post #66
post #40

Earlier quoted context omitted.

This raises an interesting paradox to me. How would the people writing the marketing copy for any product that was supposedly Superfish-resilient actually know that it was? Is the solution to simply not have marketing around such technical details? Is there a solution?

This isnt marketing peoples job. If you want a fun corporate PR check out Microsofts http://niewspierajhakera.pl/ This is a Polish anti piracy campaign equalling everyone who calls himself a Hacker to ISIS terrorist and pedophile :/ Thats right, they uploaded YT clips showing "hackers" in balaclavas collecting child porn. At the very same time Microsoft openly calls polish makers Hackers in another part of corporate…

You'd really think that was a parody website if it wasn't for the fact that the domain is indeed registered to Microsoft.
Post reply on HN