Live data from Hacker News

Remote Code Execution on Most Dell Computers

d4stiny.github.io

171–180 of 323 posts

Re: Remote Code Execution on Most Dell Computers

#171

Earlier quoted context omitted.

It works, too. This is partly why the iPhone was so popular, at first. It's been so long now that probably everyone has forgotten, but before the iPhone, essentially every smartphone on the market was fully loaded with trialware, crapware, and often had hardware features locked out by software so that you could pay extra to unlock them. I remember one particular phone that had four user-configurable hardware buttons,…

Exactly. Doing better by your customers is a differentiator. It's worked very well for Apple. Microsoft could easily take a consumer-friendly stance on OEMs preinstalling software. Microsoft please!

Microsoft themselves would have to practice that before they can preach it. All the start menu apps they try and force on users...

Re: Remote Code Execution on Most Dell Computers

#173

Earlier quoted context omitted.

>Funny, apple did this to iPod touch What feature did you pay to unlock on iPod touch? I'm struggling to remember...

Apps, initial few software updates were paid. Version 1 didn't have the app store, they pushed web apps initially

That's paying for a software update. I can understand why you're conflating the two, but I don't think it's correct to do so.

By making updates paid, Apple was charging users for work that had been done on the software side after the user made their initial purchase.

Re: Remote Code Execution on Most Dell Computers

#174
post #106

Slightly tongue in cheek to counter the anti-(Chinese/Russians) tone in recent times: Seeing how close Dell (both the company and the man) are to the US government, surely this is a backdoor by the Americans?

They can just release compromised drivers. There is no need to have a backdoor that can only be used through a non trivial exploit.

Re: Remote Code Execution on Most Dell Computers

#175

Earlier quoted context omitted.

It's odd how powerful MS is in this equation, and how the don't step in and add some sanity. It's possible to have pre-loaded software without ruining everything.

Right? MSFT could easily put an end to this nonsense.

The reason they don't apparently is that this supply chain is their bread and butter, and they don't want to mess with it.

But - I feel this is causing them harm in the long run.

I feel that there is a mostly win-win were they to step in and just try to move against the bad shenanigans. I feel that even big companies like Dell, Sony etc. shoot themselves in the foot with this stupidity.

I'm mac 10x years now, strongly looking for change, but I'm wary of that kind of Windows stupidity.

Re: Remote Code Execution on Most Dell Computers

#176

I've not yet seen anyone comment on the fact that Dell was informed in late Oct, confirmed by late Nov...and the public was advised in mid April. That's a lot of time for a known and confirmed vulnerability to be undisclosed, isn't it?

I'm not surprised in the least, they have a Bugcrowd program and I've submitted atleast one P2 that took months to fix, and best of all - they don't pay bounties! what a joke if you ask me.

Re: Remote Code Execution on Most Dell Computers

#177

OEM: Let's differentiate our otherwise commodity hw product! OEM: I know, let's add value with bundled software the customer can't uninstall! Then the bundled software turns out to (inevitably) be useless vulnerable garbage. Inevitably because a) the customer doesn't need it, b) it's engineered with all the effort that normally goes into adware for captive audiences (i.e., _minimal_), which means it will be vulnerabl…

It works, too. This is partly why the iPhone was so popular, at first. It's been so long now that probably everyone has forgotten, but before the iPhone, essentially every smartphone on the market was fully loaded with trialware, crapware, and often had hardware features locked out by software so that you could pay extra to unlock them. I remember one particular phone that had four user-configurable hardware buttons,…

>Verizon had locked them down so that they all opened the Verizon ringtone store

I had a similar issue with a phone I bought around 2005. I wanted an unlocked device, and by EU law, a carrier can't refuse to sell you that. So just pop into any store, right?

The device was unlocked but carrier branded, so the useless menu locked in place front-and-center was doubly useless because none of the carrier services worked.

I made sure to never get any phone through any carrier after that, and now that Android phones are having the same problem I'm so glad I did. Mine have always been crap free.

Re: Remote Code Execution on Most Dell Computers

#178

OEM: Let's differentiate our otherwise commodity hw product! OEM: I know, let's add value with bundled software the customer can't uninstall! Then the bundled software turns out to (inevitably) be useless vulnerable garbage. Inevitably because a) the customer doesn't need it, b) it's engineered with all the effort that normally goes into adware for captive audiences (i.e., _minimal_), which means it will be vulnerabl…

It works, too. This is partly why the iPhone was so popular, at first. It's been so long now that probably everyone has forgotten, but before the iPhone, essentially every smartphone on the market was fully loaded with trialware, crapware, and often had hardware features locked out by software so that you could pay extra to unlock them. I remember one particular phone that had four user-configurable hardware buttons,…

Even a brand new, unlocked, $1000 Samsung Galaxy S10 comes riddled with adware and spyware, some of it unremovable:

"There are apps from Flipboard and Spotify as well as a unremovable version of Facebook. McAfee Anti-virus is baked into the operating system as "security," and the Samsung Gallery app wants to share my location with Foursquare. The storage management settings, which is just a simple file-cleanup app, is "Powered by Qihoo 360," a Chinese security company. A caller-ID feature built into the phone app is provided by a company called "Hiya."

Once you run through setup and connect to Wi-Fi, the phone spawns an undismissable "Secure Wi-Fi" notification, which, it turns out, is an ad for McAfee VPN subscription service. I tried blocking the notification—it's not blockable—but it turns out you can open the advertisement, carefully consider subscribing to McAfee VPN, say "No," and then it will go away. Cool."

https://arstechnica.com/gadgets/2019/04/galaxy-s10-review-fo...

Re: Remote Code Execution on Most Dell Computers

#179

Earlier quoted context omitted.

Lenovo pulled a stunt before where they loaded their "extra software" inside UEFI to be installed by Windows after a fresh install.

My last two computers have been Lenovo ThinkPads (T520 and Yoga S1) and they bundle more crappy software than just about any other business computer maker. It's good hardware and once you reformat and reinstall Windows (or Linux) they are great machines.

I'm strongly considering the ThinkPad P1 as my next work machine -- any other issues you've experienced? I wouldn't have expected Lenovo to mess with the ThinkPad brand like that. My image of ThinkPad has always been no-nonsense, get-stuff-done, power-user-favored. Packing in a bunch of cruft doesn't seem to mesh with that image.

Re: Remote Code Execution on Most Dell Computers

#180

Earlier quoted context omitted.

It works, too. This is partly why the iPhone was so popular, at first. It's been so long now that probably everyone has forgotten, but before the iPhone, essentially every smartphone on the market was fully loaded with trialware, crapware, and often had hardware features locked out by software so that you could pay extra to unlock them. I remember one particular phone that had four user-configurable hardware buttons,…

Even a brand new, unlocked, $1000 Samsung Galaxy S10 comes riddled with adware and spyware, some of it unremovable: "There are apps from Flipboard and Spotify as well as a unremovable version of Facebook. McAfee Anti-virus is baked into the operating system as "security," and the Samsung Gallery app wants to share my location with Foursquare. The storage management settings, which is just a simple file-cleanup app, i…

That's astounding

ly bad

Post reply on HN