Live data from Hacker News

Remote Code Execution on Most Dell Computers

d4stiny.github.io

201–210 of 323 posts

Re: Remote Code Execution on Most Dell Computers

#201
post #196

Earlier quoted context omitted.

It works, too. This is partly why the iPhone was so popular, at first. It's been so long now that probably everyone has forgotten, but before the iPhone, essentially every smartphone on the market was fully loaded with trialware, crapware, and often had hardware features locked out by software so that you could pay extra to unlock them. I remember one particular phone that had four user-configurable hardware buttons,…

Yep. Only Android phones worth buying are Google/OnePlus because they don't pull that crap.

While I love oneplus, and a 5T will be my next phone, ther are not completely clean.

https://news.ycombinator.com/item?id=16240485

Re: Remote Code Execution on Most Dell Computers

#202

OEM: Let's differentiate our otherwise commodity hw product! OEM: I know, let's add value with bundled software the customer can't uninstall! Then the bundled software turns out to (inevitably) be useless vulnerable garbage. Inevitably because a) the customer doesn't need it, b) it's engineered with all the effort that normally goes into adware for captive audiences (i.e., _minimal_), which means it will be vulnerabl…

Dell sells to Enterprise A LOT. This sounds like a tool intended for behind-corporate-firewall deployment that got promoted to the public.

Enterprises will absolutely want nothing to do with this; they’ll have a team that handles endpoint provisioning and management from a gold image & other distribution tools. The endpoints will be as homogeneous as humanly possible because they are all leased in huge bulk orders, so you won’t need a tool for diverse drivers.

Besides, an end user will never have enough permission to download and install a driver - because if they did they’d be in a position to defeat the DLP, VPN posturing, shitty antivirus and disk encryption tools that have to be installed to satisfy the four nearly identical checklists produced by at least as many independent IT security organizations who most likely hired the same auditor multiple times.

Small to mid sized businesses would probably be all over this though.

Re: Remote Code Execution on Most Dell Computers

#203
post #183

Earlier quoted context omitted.

Do Google pixel phones offer an unadulterated, bloatware free Android experience?

Yes, that was always the draw of the Nexus and Pixel lines. "Vanilla Android." Really hope that's still the case, though I've switched back to iPhone for a number of reasons.

I used to buy Nexus phones and jailbreak them for SU root privileges so I could deny apps (mostly by google) from using permissions without my consent on app launch.

With that being said, I'll be switching to an iPhone for privacy reasons, starting with my next phone and I've been a loyal Android user since Google started with the G1. How times have changed...

Re: Remote Code Execution on Most Dell Computers

#204

Earlier quoted context omitted.

Dell sells to Enterprise A LOT. This sounds like a tool intended for behind-corporate-firewall deployment that got promoted to the public.

Enterprises will absolutely want nothing to do with this; they’ll have a team that handles endpoint provisioning and management from a gold image & other distribution tools. The endpoints will be as homogeneous as humanly possible because they are all leased in huge bulk orders, so you won’t need a tool for diverse drivers. Besides, an end user will never have enough permission to download and install a driver - beca…

AFAIK a fair fraction of mid-and-large enterprises use the Intel Management Engine, which seems to be considerably more dangerous than this.

It is "an autonomous subsystem ((...)) incorporated in virtually all of Intel's processor chipsets since 2008. ((One)) can use it to turn the computer on and off, and they can login remotely into the computer regardless of whether or not an operating system is installed. ((It)) always runs as long as the motherboard is receiving power, even when the computer is turned off."

According to the EFF it "has full access to memory (without the parent CPU having any knowledge); has full access to the TCP/IP stack and can send and receive network packets independently of the operating system, thus bypassing its firewall".

https://en.wikipedia.org/wiki/Intel_Management_Engine

Re: Remote Code Execution on Most Dell Computers

#205
post #183

Earlier quoted context omitted.

Do Google pixel phones offer an unadulterated, bloatware free Android experience?

As long as you don’t consider bundled Google apps bloatware, yes.

You can always build your own AOSP (which is essentially Android minus Google). In case of Pixels, this is particularly easy. I use a Pixel to avoid Google, which is a bit paradoxical.

Re: Remote Code Execution on Most Dell Computers

#206
post #122

Earlier quoted context omitted.

Your approach won’t solve that, you’d need to also flash the chip with patched / clean firmware

The EFI partition is on disk, not in firmware.

Clearly there's some component of UEFI that's in firmware, right? I don't really know all the terminology and such here, so please correct my understanding, but -- even if you don't have a disk, you'll get some UEFI bootloader. I seem to recall that some devices like many Chromebooks will have some extensive EFI blobs in firmware partitions, at least some of which is a read-only "get back to factory settings if you really screw up" stuff. I don't see what could stop a vendor from putting whatever they want into a a read-only firmware EFI partition, I'm pretty sure they exist in the wild.

Re: Remote Code Execution on Most Dell Computers

#207
post #199

Earlier quoted context omitted.

Even a brand new, unlocked, $1000 Samsung Galaxy S10 comes riddled with adware and spyware, some of it unremovable: "There are apps from Flipboard and Spotify as well as a unremovable version of Facebook. McAfee Anti-virus is baked into the operating system as "security," and the Samsung Gallery app wants to share my location with Foursquare. The storage management settings, which is just a simple file-cleanup app, i…

I don't understand why folks subject themselves to this for $1000 when other options are available. You don’t have to keep supporting Samsung by buying their phones. Get a pixel instead.

I got an S10 because of the headphone jack and sd card slot. I uninstalled or disabled any software I didn't need pretty easily. I find it to be a fantastic phone.

Re: Remote Code Execution on Most Dell Computers

#208
post #67

Earlier quoted context omitted.

The author chose to download the software from the OEM and the software can be uninstalled.

> The author chose to download the software from the OEM and the software can be uninstalled. I take issue with that. Apx. one year ago it was using excessive CPU on my Dell. I tried to uninstall, but the uninstaller crashed. I turned to dell.com and then google. Turned out that throusands of people had the same problem, but no solution from Dell. This is a sorry PoS application. In my experience, OEMs like Dell, HP…

The blog post isn't about your experience, it's about the blog post author's experience.

Do try to stay on target when communicating with people. It is impolite to suddenly change a topic of discussion to yourself.

Re: Remote Code Execution on Most Dell Computers

#209
post #109

OEM: Let's differentiate our otherwise commodity hw product! OEM: I know, let's add value with bundled software the customer can't uninstall! Then the bundled software turns out to (inevitably) be useless vulnerable garbage. Inevitably because a) the customer doesn't need it, b) it's engineered with all the effort that normally goes into adware for captive audiences (i.e., _minimal_), which means it will be vulnerabl…

In both the phone and PC space I do not understand the need to do this at all. There is commoditization of the market on the low end, but high end products that compete with iphones and macbooks are definitely not commodity and there is ample differentiation to be had on quality where mindshare can reap substantial margins on a smart investment of good design.

There is no need for this stuff, of course. It's added because marketing want to improve the company's image in the eye of Joe/Jane Consumer, and probably someone in a support organization was honestly trying to make a customer's life easier. It was just implemented poorly.

The day that hardware vendors get over the idea that they need to "add value" to software that they resell will be a very good day for everyone.

Re: Remote Code Execution on Most Dell Computers

#210
post #106

Slightly tongue in cheek to counter the anti-(Chinese/Russians) tone in recent times: Seeing how close Dell (both the company and the man) are to the US government, surely this is a backdoor by the Americans?

Is the anti-China or anti-Russia unwarranted? Dell fucked up and should be held accountable. Being in America they will more than likely face legal action of some sort over this. I would hope so anyway.

It's really hypocritical to call out Chinese companies for spying on people when most American tech companies spy on their users.
Post reply on HN