Live data from Hacker News

Remote Code Execution on Most Dell Computers

d4stiny.github.io

51–60 of 323 posts

Re: Remote Code Execution on Most Dell Computers

#51

Earlier quoted context omitted.

Lenovo pulled a stunt before where they loaded their "extra software" inside UEFI to be installed by Windows after a fresh install.

That caused so much of a backlash that they released a new BIOS version without that stuff. As was absolutely fair. Abusing Windows' ability to obtain HW-drivers though UEFI (something which can be used for good) to bundle shit-ware is just absolutely rotten.

I wouldn't call that good. More like a bad solution to a problem which shouldn't exist. Nothing should ever be located in system firmware save for the boot firmware and perhaps a basic diagnostic tool like memtest.

Re: Remote Code Execution on Most Dell Computers

#52

OEM: Let's differentiate our otherwise commodity hw product! OEM: I know, let's add value with bundled software the customer can't uninstall! Then the bundled software turns out to (inevitably) be useless vulnerable garbage. Inevitably because a) the customer doesn't need it, b) it's engineered with all the effort that normally goes into adware for captive audiences (i.e., _minimal_), which means it will be vulnerabl…

You forgot the last part:

OEM: Profit

Re: Remote Code Execution on Most Dell Computers

#54
post #13

Earlier quoted context omitted.

That’s astounding. Suddenly my “zero the entire storage, including partition table” methodology which I always somewhat regarded as overkill appears to be reasonable and/or necessary.

Such are the problems Purism is said to be attacking: https://puri.sm/products/librem-13/

For anyone who has bought one of their laptops, how does the build quality compare to an old macbook or thinkpad?

Re: Remote Code Execution on Most Dell Computers

#56

OEM: Let's differentiate our otherwise commodity hw product! OEM: I know, let's add value with bundled software the customer can't uninstall! Then the bundled software turns out to (inevitably) be useless vulnerable garbage. Inevitably because a) the customer doesn't need it, b) it's engineered with all the effort that normally goes into adware for captive audiences (i.e., _minimal_), which means it will be vulnerabl…

You forgot the last part: OEM: Profit

it's almost a psychology experiment where brands con you just enough and let you absorb the pain long enough that they forgot and start browsing for a new machine, repeating the cycle

Re: Remote Code Execution on Most Dell Computers

#57

This is exactly why you should remove any bundled software from vendors and try to start afresh when picking up a new machine.

Lenovo pulled a stunt before where they loaded their "extra software" inside UEFI to be installed by Windows after a fresh install.

> Lenovo pulled a stunt before where they loaded their "extra software" inside UEFI to be installed by Windows after a fresh install.

Holy cow. Would you have a link on this?

Re: Remote Code Execution on Most Dell Computers

#58
post #36

General sanity aside, the whole exploit hinges on the fact that they used string parsing to check for the prefix "http". This wouldn't have been exploitable if they used a proper URL library.

Do you think that a proper Url library would have protected against a MITM’d DNS attack?

It that library allowed them to enforce connection via HTTPS, then yes.

Re: Remote Code Execution on Most Dell Computers

#59

This is exactly why you should remove any bundled software from vendors and try to start afresh when picking up a new machine.

Lenovo pulled a stunt before where they loaded their "extra software" inside UEFI to be installed by Windows after a fresh install.

Lenovo has a program basically identical to this. I wonder if it’s got any of the same problems as the Dell version.

Re: Remote Code Execution on Most Dell Computers

#60

Earlier quoted context omitted.

Lenovo pulled a stunt before where they loaded their "extra software" inside UEFI to be installed by Windows after a fresh install.

> Lenovo pulled a stunt before where they loaded their "extra software" inside UEFI to be installed by Windows after a fresh install. Holy cow. Would you have a link on this?

The tech is called Windows Platform Binary Table, WPBT for short.

Here's a random article covering it https://www.howtogeek.com/226308/the-windows-platform-binary...

You can find others by searching for "lenovo wpbt" or "lenovo unremovable crapware".

Post reply on HN