Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Dell installs self-signed root certificate on laptops, endangering users' privacy
PC World ^ | 11/23/15 | Lucian Constantin

Posted on 11/23/2015 6:44:59 PM PST by markomalley

Dell laptops are coming preloaded with a self-signed root digital certificate that lets attackers spy on traffic to any secure website.

The reports first surfaced on Reddit and were soon confirmed by other users and security experts on Twitter and blogs. The root certificate, which has the power of a certificate authority on the laptops it's installed on, comes bundled with its corresponding private key, making the situation worse.

With the private key, which is now available online, anyone can generate a certificate for any website that will be trusted by browsers such as Internet Explorer and Google Chrome that use the Windows certificate store on affected laptops. Security experts have already generated proof-of-concept certificates for *.google.com and bankofamerica.com.

The certificate, which is called eDellRoot, was added to Dell consumer and commercial devices starting in August with the intention of providing better customer support, Dell said in an emailed statement: "When a PC engages with Dell online support, the certificate provides the system service tag allowing Dell online support to immediately identify the PC model, drivers, OS, hard drive, etc. making it easier and faster to service."

(Excerpt) Read more at pcworld.com ...


TOPICS: Business/Economy; Government
KEYWORDS: certificate; certificateauthority; dell; dudeyergettinadell; privacy; rootcert; selfsignedcert; windows; windowspinglist
Navigation: use the links below to view more comments.
first previous 1-2021-32 last
To: dayglored

Yup, good hardware. And a data center won’t get metal with pre-installed OSs.


21 posted on 11/23/2015 8:29:43 PM PST by Gene Eric (Don't be a statist!)
[ Post Reply | Private Reply | To 20 | View Replies]

To: UB355
My two year old dell 1500 series laptop does not have the cert

Inspiron 5558. There it sits in the console like a turd in the punch bowl.

22 posted on 11/23/2015 8:34:14 PM PST by Stentor ("The best lack all conviction, while the worst are full of passionate intensity.")
[ Post Reply | Private Reply | To 19 | View Replies]

To: driftdiver
I bought a Dell fall a year ago with Windows 8.1. Now, I have the option of converting to Win 10 at no expense & had signed up to do it, but then started reading about all the privacy issues. I use Classic Shell to make Win 8.1 look like 7 (which is what my old laptop was on before it crashed) & I've gotten used to it. I decided I wasn't going to 10 & cancelled out. Evidently, you can disable a lot of the Win 10 features that affect privacy, but it's not an easy thing to do and not all in one place. Here's the article that changed my mind about going to 10:

Everything You Need to Disable in Windows 10

23 posted on 11/23/2015 9:15:45 PM PST by Qiviut
[ Post Reply | Private Reply | To 8 | View Replies]

To: Qiviut

Thanks for that link. Good article.


24 posted on 11/23/2015 9:39:14 PM PST by TChad
[ Post Reply | Private Reply | To 23 | View Replies]

To: markomalley
Dell security error widens as researchers dig deeper (Earlier problem is worse than was thought)

Duo Security researchers found a second weak digital certificate on a new Dell Inspiron laptop

The fallout from a serious security mistake made by Dell is widening, as security experts find more issues of concern.

Followup thread on the expanded problem:

http://www.freerepublic.com/focus/chat/3364271/posts

25 posted on 11/23/2015 9:58:56 PM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored
That's Obama-level stupid.
26 posted on 11/23/2015 11:21:11 PM PST by grey_whiskers (The opinions are solely those of the author and are subject to change without notice.)
[ Post Reply | Private Reply | To 20 | View Replies]

To: grey_whiskers
> That's Obama-level stupid.

Yeah, but give the man credit for effort -- it takes a lot of hard work to consistently be that stupid.

27 posted on 11/23/2015 11:23:25 PM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 26 | View Replies]

To: markomalley

fl


28 posted on 11/24/2015 1:58:45 AM PST by maine-iac7
[ Post Reply | Private Reply | To 1 | View Replies]

To: Rebelbase

Dude, you’re getting a cell!

http://www.cnn.com/2003/LAW/02/10/dell.dude.arrest/


29 posted on 11/24/2015 3:29:16 AM PST by Fresh Wind (Falcon 105)
[ Post Reply | Private Reply | To 4 | View Replies]

To: markomalley

bfl


30 posted on 11/24/2015 4:45:12 AM PST by ImNotLying
[ Post Reply | Private Reply | To 1 | View Replies]

To: markomalley; rdb3; Calvinist_Dark_Lord; JosephW; Only1choice____Freedom; amigatec; ...

31 posted on 11/24/2015 5:41:13 AM PST by ShadowAce (Linux - The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: markomalley

FYI

Majorgeeks.com has an eDellRoot Certificate Fix, apparently released by Dell:

http://www.majorgeeks.com/files/details/edellroot_certificate_fix.html


32 posted on 11/24/2015 6:52:33 AM PST by TomGuy
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-32 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson