Live data from Hacker News

Remote Code Execution on Most Dell Computers

d4stiny.github.io

191–200 of 323 posts

Re: Remote Code Execution on Most Dell Computers

#191
post #183

Earlier quoted context omitted.

Even a brand new, unlocked, $1000 Samsung Galaxy S10 comes riddled with adware and spyware, some of it unremovable: "There are apps from Flipboard and Spotify as well as a unremovable version of Facebook. McAfee Anti-virus is baked into the operating system as "security," and the Samsung Gallery app wants to share my location with Foursquare. The storage management settings, which is just a simple file-cleanup app, i…

Do Google pixel phones offer an unadulterated, bloatware free Android experience?

As long as you don’t consider bundled Google apps bloatware, yes.

Re: Remote Code Execution on Most Dell Computers

#192

Earlier quoted context omitted.

>Funny, apple did this to iPod touch What feature did you pay to unlock on iPod touch? I'm struggling to remember...

Apps, initial few software updates were paid. Version 1 didn't have the app store, they pushed web apps initially

They charged for OS upgrades to be compliant with I believed the Sarbanes-Oxley Act. As providing free upgrades would amount to pre booking revenue.

Re: Remote Code Execution on Most Dell Computers

#193

Earlier quoted context omitted.

Second product for this mythical OEM should just be a TV with an instant-on button and as many hdmi ports that will fit given a small-as-possible bezel. One model per year per common size->one price. Big sale on thanksgiving and then the slightly better ones come out.

> a TV with an instant-on button Please . I use a 4k TV as my computer monitor. It's works fairly well for that because I researched it and found a good fit, but I use a remote to start it every time, and it takes 15-20 seconds before it's ready to receive input. That's a long time to be sitting in front of your computer waiting, especially when it happens 3-10 times a day.

It's because TVs have become computers with a display.

Try an analog TV and you'll see real speed!

Re: Remote Code Execution on Most Dell Computers

#194

OEM: Let's differentiate our otherwise commodity hw product! OEM: I know, let's add value with bundled software the customer can't uninstall! Then the bundled software turns out to (inevitably) be useless vulnerable garbage. Inevitably because a) the customer doesn't need it, b) it's engineered with all the effort that normally goes into adware for captive audiences (i.e., _minimal_), which means it will be vulnerabl…

Can someone repost this with normal quotes? On my phone

Re: Remote Code Execution on Most Dell Computers

#195
post #88

This is exactly why you should remove any bundled software from vendors and try to start afresh when picking up a new machine.

Unfortunately I have a MacBook and Apple won't even let me uninstall the chess program bundled with macOS.

It's barely 5 megabytes.. and it's probably not connecting to anything.

The protections for pre-installed apps help to make sure nothing else tampers with them, e.g. injecting some malware, but I'm sure you can remove those protections and reclaim the 5 MB if you really wanted to.

https://developer.apple.com/library/archive/documentation/Se...

Re: Remote Code Execution on Most Dell Computers

#196

OEM: Let's differentiate our otherwise commodity hw product! OEM: I know, let's add value with bundled software the customer can't uninstall! Then the bundled software turns out to (inevitably) be useless vulnerable garbage. Inevitably because a) the customer doesn't need it, b) it's engineered with all the effort that normally goes into adware for captive audiences (i.e., _minimal_), which means it will be vulnerabl…

It works, too. This is partly why the iPhone was so popular, at first. It's been so long now that probably everyone has forgotten, but before the iPhone, essentially every smartphone on the market was fully loaded with trialware, crapware, and often had hardware features locked out by software so that you could pay extra to unlock them. I remember one particular phone that had four user-configurable hardware buttons,…

Yep. Only Android phones worth buying are Google/OnePlus because they don't pull that crap.

Re: Remote Code Execution on Most Dell Computers

#198

Earlier quoted context omitted.

It doesn't even need a library. A simple regex would have prevented this.

A naive regex would just as easily have exactly the same issue, e.g. "^http:"

That wouldn't have the same issue since the space at the beginning would fail that regex.

Re: Remote Code Execution on Most Dell Computers

#199

Earlier quoted context omitted.

It works, too. This is partly why the iPhone was so popular, at first. It's been so long now that probably everyone has forgotten, but before the iPhone, essentially every smartphone on the market was fully loaded with trialware, crapware, and often had hardware features locked out by software so that you could pay extra to unlock them. I remember one particular phone that had four user-configurable hardware buttons,…

Even a brand new, unlocked, $1000 Samsung Galaxy S10 comes riddled with adware and spyware, some of it unremovable: "There are apps from Flipboard and Spotify as well as a unremovable version of Facebook. McAfee Anti-virus is baked into the operating system as "security," and the Samsung Gallery app wants to share my location with Foursquare. The storage management settings, which is just a simple file-cleanup app, i…

I don't understand why folks subject themselves to this for $1000 when other options are available.

You don’t have to keep supporting Samsung by buying their phones. Get a pixel instead.

Re: Remote Code Execution on Most Dell Computers

#200

OEM: Let's differentiate our otherwise commodity hw product! OEM: I know, let's add value with bundled software the customer can't uninstall! Then the bundled software turns out to (inevitably) be useless vulnerable garbage. Inevitably because a) the customer doesn't need it, b) it's engineered with all the effort that normally goes into adware for captive audiences (i.e., _minimal_), which means it will be vulnerabl…

Dell sells to Enterprise A LOT. This sounds like a tool intended for behind-corporate-firewall deployment that got promoted to the public.

No, they have other tools for enterprise, or in some IT departments buy third party tools off the shelf for this purpose.
Post reply on HN