Live data from Hacker News

Remote Code Execution on Most Dell Computers

d4stiny.github.io

181–190 of 323 posts

Re: Remote Code Execution on Most Dell Computers

#182
post #171

Earlier quoted context omitted.

Exactly. Doing better by your customers is a differentiator. It's worked very well for Apple. Microsoft could easily take a consumer-friendly stance on OEMs preinstalling software. Microsoft please!

Microsoft themselves would have to practice that before they can preach it. All the start menu apps they try and force on users...

Microsoft is changing lately.

Re: Remote Code Execution on Most Dell Computers

#183

Earlier quoted context omitted.

It works, too. This is partly why the iPhone was so popular, at first. It's been so long now that probably everyone has forgotten, but before the iPhone, essentially every smartphone on the market was fully loaded with trialware, crapware, and often had hardware features locked out by software so that you could pay extra to unlock them. I remember one particular phone that had four user-configurable hardware buttons,…

Even a brand new, unlocked, $1000 Samsung Galaxy S10 comes riddled with adware and spyware, some of it unremovable: "There are apps from Flipboard and Spotify as well as a unremovable version of Facebook. McAfee Anti-virus is baked into the operating system as "security," and the Samsung Gallery app wants to share my location with Foursquare. The storage management settings, which is just a simple file-cleanup app, i…

Do Google pixel phones offer an unadulterated, bloatware free Android experience?

Re: Remote Code Execution on Most Dell Computers

#184
post #43

Earlier quoted context omitted.

Microsoft should prevent this. It's not in their interest to allow OEMs to circumvent the normal software installation methods for Windows. It should be prohibited in whatever agreement OEMs make with Microsoft, and maybe Windows should prevent execution of such code if it's possible to tell it apart from drivers.

Pretty sure there was a USG lawsuit about what MSFT could require from OEMs.

I don't think that settlement applies to this. The OEM part of that lawsuit, from my recollection, hinged on the fact that Microsoft's OEM licenses required that the OEM limit the percentage of computers they sold without a Windows OS pre-installed. I don't remember there being anything about how OEMs use their APIs.

I think it would be perfectly fair for Microsoft to require OEM licensees to not use that feature for shitware installations. I can't see how that would fall afoul of antitrust or related regulations. Maybe I'm wrong though, that was a while ago and it wasn't my specialty when I practiced law.

Re: Remote Code Execution on Most Dell Computers

#185

Earlier quoted context omitted.

It works, too. This is partly why the iPhone was so popular, at first. It's been so long now that probably everyone has forgotten, but before the iPhone, essentially every smartphone on the market was fully loaded with trialware, crapware, and often had hardware features locked out by software so that you could pay extra to unlock them. I remember one particular phone that had four user-configurable hardware buttons,…

Even a brand new, unlocked, $1000 Samsung Galaxy S10 comes riddled with adware and spyware, some of it unremovable: "There are apps from Flipboard and Spotify as well as a unremovable version of Facebook. McAfee Anti-virus is baked into the operating system as "security," and the Samsung Gallery app wants to share my location with Foursquare. The storage management settings, which is just a simple file-cleanup app, i…

It was bad enough with the fucking Bixby button that can't be disabled on my Samsung S8 Active. Hearing about the S10 solidifies that my next phone will absolutely not be a Samsung. Which is a shame since the hardware is otherwise great.

Re: Remote Code Execution on Most Dell Computers

#186

Nice writeup! Only feedback is it seems like you dont need to dna hijack anything. Seems like you can just register localhost-lollolanything.com and pull the attack off, no?

There's code that checks for the domain ending in .dell.com (etc) so it wouldn't work.

Re: Remote Code Execution on Most Dell Computers

#188
post #183

Earlier quoted context omitted.

Even a brand new, unlocked, $1000 Samsung Galaxy S10 comes riddled with adware and spyware, some of it unremovable: "There are apps from Flipboard and Spotify as well as a unremovable version of Facebook. McAfee Anti-virus is baked into the operating system as "security," and the Samsung Gallery app wants to share my location with Foursquare. The storage management settings, which is just a simple file-cleanup app, i…

Do Google pixel phones offer an unadulterated, bloatware free Android experience?

Yes, that was always the draw of the Nexus and Pixel lines. "Vanilla Android." Really hope that's still the case, though I've switched back to iPhone for a number of reasons.
Post reply on HN