Live data from Hacker News

Remote Code Execution on Most Dell Computers

d4stiny.github.io

101–110 of 323 posts

Re: Remote Code Execution on Most Dell Computers

#101

Earlier quoted context omitted.

After a quick gander, I'm actually more interested in their phone. The idea of a phone that can not and will not track me, and which I know is doing only what I want it to do is pretty damned exciting. The laptop is certainly nice though.

If it has a SIM card, it is tracking you. If you leave Bluetooth or WiFi enabled, then it is being tracked. All the Librem 5 can do is 1) give trusted RF kill switches, and 2) not add additional tracking on top. I will probably still buy one if it materializes, and is functional.

> If you leave Bluetooth ... enabled, then it is being tracked.

Wait, can you expand on this? Are you saying (current, existing) Bluetooth radios can be used for location tracking without additional hardware/OS support?

Re: Remote Code Execution on Most Dell Computers

#102
post #67

OEM: Let's differentiate our otherwise commodity hw product! OEM: I know, let's add value with bundled software the customer can't uninstall! Then the bundled software turns out to (inevitably) be useless vulnerable garbage. Inevitably because a) the customer doesn't need it, b) it's engineered with all the effort that normally goes into adware for captive audiences (i.e., _minimal_), which means it will be vulnerabl…

The author chose to download the software from the OEM and the software can be uninstalled.

> The author chose to download the software from the OEM and the software can be uninstalled.

I take issue with that. Apx. one year ago it was using excessive CPU on my Dell. I tried to uninstall, but the uninstaller crashed.

I turned to dell.com and then google. Turned out that throusands of people had the same problem, but no solution from Dell.

This is a sorry PoS application. In my experience, OEMs like Dell, HP create horrible software and drivers.

https://www.google.com/search?q=can%27t+uninstall+dell+suppo...

Re: Remote Code Execution on Most Dell Computers

#103

Earlier quoted context omitted.

Your approach won’t solve that, you’d need to also flash the chip with patched / clean firmware

Short of flashing the chip, which is impractical, are there any other "imperfect but probably sufficient" workarounds? For example, would loading Grub first, and then loading Windows from Grub, prevent the issue?

Basically none. You’ve got the ME (or AMD’s equivalent) on the CPU anyway so you really can’t avoid having some kind of root kit. Older Intel hardware that doesn’t have the ME or can be neutered is the best bet, and these machines don’t use UEFI anyway. Otherwise you could go for a non-Intel/AMD architecture, but there aren’t that many of those around anymore.

Re: Remote Code Execution on Most Dell Computers

#104
post #101

Earlier quoted context omitted.

If it has a SIM card, it is tracking you. If you leave Bluetooth or WiFi enabled, then it is being tracked. All the Librem 5 can do is 1) give trusted RF kill switches, and 2) not add additional tracking on top. I will probably still buy one if it materializes, and is functional.

> If you leave Bluetooth ... enabled, then it is being tracked. Wait, can you expand on this? Are you saying (current, existing) Bluetooth radios can be used for location tracking without additional hardware/OS support?

Maybe the MAC address or other broadcasted information could be used to fingerprint your device. That’s why WiFi MAC addresses are randomized on iOS, but I’m not sure that Bluetooth has gotten the same treatment.

Re: Remote Code Execution on Most Dell Computers

#105
post #100
post #98

Earlier quoted context omitted.

I just checked on my Dell workstation at work and it seems they are now using this method to load the Lojack anti theft rootkit. I see the wpbbin.exe file and it's signed by Absolute Software. I guess that is what the feature is designed for, though.

Many computer manufacturers seem to do this at least. There might be a way to trick the UEFI into thinking that you’re installing a non-Windows OS but I’m not sure.

You got it completely backwards.

UEFI doesn't install anything. It provides a machine-specific binary for Windows to install (intended to ensure that Windows has proper drivers for all the machine’s hardware).

Windows then decides to install this, based on the assumption that OEMs won’t bundle non-critical shit-ware using this method. Which has turned out to be the faulty assumption here.

Either way: Use any other OS except Windows and these UEFI-bundled binaries does nothing. They’re duds.

UEFI doesn’t need to be “tricked” and it can’t force the installation of anything into an OS not wanting it.

It’s really simple, so no need to invent overly complicated threat models.

Re: Remote Code Execution on Most Dell Computers

#107

First off, great article. But, like so many other articles about security vulnerabilities, there seems to be a general attitude among most people (including many IT shops) that "it's an isolated incident", and "the experts will fix it...". "It's an isolated incident", and "The experts will fix it...". They said the same thing about Spectre, Meltdown, Rowhammer attacks, what have you. "It's an isolated incident", and…

Well I think it's very possible that backdoors are set up by governments like you say.

But I also think that even if they don't, it also seems very possible that vulnerabilities are quite common as mistakes. Just due to the realities of security.

In my opinion security is much more difficult than people realize.

For example in this case there seems to be a majority opinion something along the lines of "What an idiot! _I_ would never make that mistake!". It's much easier to say that in hindsight than it is to really execute secure code that no one can defeat. The response might be "well, no one broke into any of _my_ systems so far" and I would say .. how do you know they didn't? And also, maybe no one bothered to try to exploit you because you are not a high value target. Or they are just busy and will get to trying to penetrate you next week.

I think this is due to the complexity of software and IT rather than general negligence.

Re: Remote Code Execution on Most Dell Computers

#108
post #100

Earlier quoted context omitted.

Many computer manufacturers seem to do this at least. There might be a way to trick the UEFI into thinking that you’re installing a non-Windows OS but I’m not sure.

You got it completely backwards. UEFI doesn't install anything. It provides a machine-specific binary for Windows to install (intended to ensure that Windows has proper drivers for all the machine’s hardware). Windows then decides to install this, based on the assumption that OEMs won’t bundle non-critical shit-ware using this method. Which has turned out to be the faulty assumption here. Either way: Use any other OS…

I think the parent is getting confused because previously Lojack did work as they describe, by injecting its binaries into the filesystem like that. But I guess they have now switched to using this WPBT feature instead.

Re: Remote Code Execution on Most Dell Computers

#109

OEM: Let's differentiate our otherwise commodity hw product! OEM: I know, let's add value with bundled software the customer can't uninstall! Then the bundled software turns out to (inevitably) be useless vulnerable garbage. Inevitably because a) the customer doesn't need it, b) it's engineered with all the effort that normally goes into adware for captive audiences (i.e., _minimal_), which means it will be vulnerabl…

In both the phone and PC space I do not understand the need to do this at all. There is commoditization of the market on the low end, but high end products that compete with iphones and macbooks are definitely not commodity and there is ample differentiation to be had on quality where mindshare can reap substantial margins on a smart investment of good design.

Re: Remote Code Execution on Most Dell Computers

#110
post #67

OEM: Let's differentiate our otherwise commodity hw product! OEM: I know, let's add value with bundled software the customer can't uninstall! Then the bundled software turns out to (inevitably) be useless vulnerable garbage. Inevitably because a) the customer doesn't need it, b) it's engineered with all the effort that normally goes into adware for captive audiences (i.e., _minimal_), which means it will be vulnerabl…

The author chose to download the software from the OEM and the software can be uninstalled.

"The agent wasn’t installed on my computer because it was a fresh Windows installation, but I decided to install it to investigate further."
Post reply on HN