Live data from Hacker News

Remote Code Execution on Most Dell Computers

d4stiny.github.io

211–220 of 323 posts

Re: Remote Code Execution on Most Dell Computers

#211

General sanity aside, the whole exploit hinges on the fact that they used string parsing to check for the prefix "http". This wouldn't have been exploitable if they used a proper URL library.

The sane thing would have been to not use a HTTP server at all. This part is pure laziness. It is trivial to communicate with a Windows service locally through named pipes.

I think you're referring to the SupportAssist Client being an HTTP server - while it is weird that they exposed all those other routes, the driver install route allows for drivers to be installed from a website (which a named pipe would not).

I wouldn't characterize it as "pure laziness" - more a questionable feature

Re: Remote Code Execution on Most Dell Computers

#212
post #199

Earlier quoted context omitted.

Even a brand new, unlocked, $1000 Samsung Galaxy S10 comes riddled with adware and spyware, some of it unremovable: "There are apps from Flipboard and Spotify as well as a unremovable version of Facebook. McAfee Anti-virus is baked into the operating system as "security," and the Samsung Gallery app wants to share my location with Foursquare. The storage management settings, which is just a simple file-cleanup app, i…

I don't understand why folks subject themselves to this for $1000 when other options are available. You don’t have to keep supporting Samsung by buying their phones. Get a pixel instead.

Google branded hardware has a notorious reputation for problems about 1-1.5 year down the road. This has happened with every single Google device anyone in my family has ever owned and so we've basically stopped buying Google. Very few manufacturers apart from Samsung come close to Apple in terms of sheer hardware quality and service support and Apple OS's lack of customisability, pathetic camera and lack of 3.5mm jack completely rules it out for me. That's basically why I have paid a premium for Samsung over the years. I may look at Huawei too now that they appear to have significantly upped the hardware quality game.

Being virtually stock Android, pre-installed software is easily disabled (even FB) - the only major complaint is inability to assign Bixby button to something else without rooting.

Re: Remote Code Execution on Most Dell Computers

#213
post #203

Earlier quoted context omitted.

Yes, that was always the draw of the Nexus and Pixel lines. "Vanilla Android." Really hope that's still the case, though I've switched back to iPhone for a number of reasons.

I used to buy Nexus phones and jailbreak them for SU root privileges so I could deny apps (mostly by google) from using permissions without my consent on app launch. With that being said, I'll be switching to an iPhone for privacy reasons, starting with my next phone and I've been a loyal Android user since Google started with the G1. How times have changed...

You can use LineageOS for a zero-GOOG experience from first run without uninstalling anything.

Re: Remote Code Execution on Most Dell Computers

#214
post #212
post #199

Earlier quoted context omitted.

I don't understand why folks subject themselves to this for $1000 when other options are available. You don’t have to keep supporting Samsung by buying their phones. Get a pixel instead.

Google branded hardware has a notorious reputation for problems about 1-1.5 year down the road. This has happened with every single Google device anyone in my family has ever owned and so we've basically stopped buying Google. Very few manufacturers apart from Samsung come close to Apple in terms of sheer hardware quality and service support and Apple OS's lack of customisability, pathetic camera and lack of 3.5mm ja…

It's now possible to reassign the bixby button to something else without rooting the phone.

Re: Remote Code Execution on Most Dell Computers

#215

Earlier quoted context omitted.

Is the anti-China or anti-Russia unwarranted? Dell fucked up and should be held accountable. Being in America they will more than likely face legal action of some sort over this. I would hope so anyway.

It's really hypocritical to call out Chinese companies for spying on people when most American tech companies spy on their users.

Yeah but here we call it "analytics", not spying!

Re: Remote Code Execution on Most Dell Computers

#217
post #67

OEM: Let's differentiate our otherwise commodity hw product! OEM: I know, let's add value with bundled software the customer can't uninstall! Then the bundled software turns out to (inevitably) be useless vulnerable garbage. Inevitably because a) the customer doesn't need it, b) it's engineered with all the effort that normally goes into adware for captive audiences (i.e., _minimal_), which means it will be vulnerabl…

The author chose to download the software from the OEM and the software can be uninstalled.

>The author chose to download the software from the OEM

Is a user expecting to be able to trust their manufacturer an unreasonable?

Re: Remote Code Execution on Most Dell Computers

#218

OEM: Let's differentiate our otherwise commodity hw product! OEM: I know, let's add value with bundled software the customer can't uninstall! Then the bundled software turns out to (inevitably) be useless vulnerable garbage. Inevitably because a) the customer doesn't need it, b) it's engineered with all the effort that normally goes into adware for captive audiences (i.e., _minimal_), which means it will be vulnerabl…

It works, too. This is partly why the iPhone was so popular, at first. It's been so long now that probably everyone has forgotten, but before the iPhone, essentially every smartphone on the market was fully loaded with trialware, crapware, and often had hardware features locked out by software so that you could pay extra to unlock them. I remember one particular phone that had four user-configurable hardware buttons,…

There were smartphones before the iPhone?

Re: Remote Code Execution on Most Dell Computers

#219

Earlier quoted context omitted.

My last two computers have been Lenovo ThinkPads (T520 and Yoga S1) and they bundle more crappy software than just about any other business computer maker. It's good hardware and once you reformat and reinstall Windows (or Linux) they are great machines.

I'm strongly considering the ThinkPad P1 as my next work machine -- any other issues you've experienced? I wouldn't have expected Lenovo to mess with the ThinkPad brand like that. My image of ThinkPad has always been no-nonsense, get-stuff-done, power-user-favored. Packing in a bunch of cruft doesn't seem to mesh with that image.

> I wouldn't have expected Lenovo to mess with the ThinkPad brand like that. My image of ThinkPad has always been no-nonsense, get-stuff-done, power-user-favored.

I used to think the same until I got a T480. I was drawn to it because it was one of the few laptops that still has a direct hardware Function-key row (I use linux, so software Function Keys are not fun).

The keyboard, while mechanically excellent, is horribly designed if you depend on it to do your job: They "innovated" by moving the Home/End keys up to the Function row, they "innovated" by completely removing the context menu key from the keyboard and placing the PrintScreen key (of all things) in its place, and they also placed the Fn key at the bottom left corner of the keyboard where Ctrl is usually located (you can fortunately swap Ctrl/Fn with each other in the bios, so the last one isn't a issue if you're willing to live with mislabeled keys).

If you're a heavy keyboard user, I strongly suggest properly testing a laptop's keyboard before buying.

Re: Remote Code Execution on Most Dell Computers

#220

Earlier quoted context omitted.

Enterprises will absolutely want nothing to do with this; they’ll have a team that handles endpoint provisioning and management from a gold image & other distribution tools. The endpoints will be as homogeneous as humanly possible because they are all leased in huge bulk orders, so you won’t need a tool for diverse drivers. Besides, an end user will never have enough permission to download and install a driver - beca…

AFAIK a fair fraction of mid-and-large enterprises use the Intel Management Engine, which seems to be considerably more dangerous than this. It is "an autonomous subsystem ((...)) incorporated in virtually all of Intel's processor chipsets since 2008. ((One)) can use it to turn the computer on and off, and they can login remotely into the computer regardless of whether or not an operating system is installed. ((It))…

I regret if my comment was misconstrued - I'm not claiming enterprises wouldn't use this specific tool because it is dangerous. I'm claiming they wouldn't use this specific tool because it does not fit within the "how do I manage tens of thousands of endpoints while meeting multiple defined and audited security and compliance goals" box.

You might even say that quality and security are orthogonal, at least in this particular case. That might not even be wrong.

Post reply on HN