Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Dell security error widens as researchers dig deeper (Earlier problem is worse than was thought)
PCWorld ^ | Nov 23, 2015 | Jeremy Kirk

Posted on 11/23/2015 9:56:26 PM PST by dayglored

Duo Security researchers found a second weak digital certificate on a new Dell Inspiron laptop

The fallout from a serious security mistake made by Dell is widening, as security experts find more issues of concern.

Researchers with Duo Security have found a second weak digital certificate in a new Dell laptop and evidence of another problematic one circulating.

The issue started after it was discovered Dell shipped devices with a self-signed root digital certificate, eDellRoot, which is used to encrypt data traffic. But it installed the root certificate with the private encryption key included, a critical error that left many security experts aghast.

The company acknowledged the problem on Monday and said it plans to issue instructions for how to permanently remove the certificate.

The security implications are serious. Attackers could use the private key to create their own digital certificates that could be used to make spoof websites appear legitimate.

It would also be possible to conduct a man-in-the-middle attack, spying on data traffic coming from computers on which the certificate is installed.

(Much more detail at the link)

(Excerpt) Read more at pcworld.com ...


TOPICS: Business/Economy; Computers/Internet; Hobbies
KEYWORDS: computer; dell; dudeyergettinadell; internet; laptop; malware; tech; windows; windowspinglist
This is a followup to the thread posted earlier on the first Dell problem:

http://www.freerepublic.com/focus/news/3364218/posts

because the problem has turned into something even worse.

1 posted on 11/23/2015 9:56:27 PM PST by dayglored
[ Post Reply | Private Reply | View Replies]

To: dayglored; Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; Alas Babylon!; amigatec; ...
Looks like Dell made a number of egregious security errors ... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

2 posted on 11/23/2015 9:57:17 PM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

And all this time I thought the man in the middle was from homeland security. Or the muslims. Or both.


3 posted on 11/23/2015 10:22:53 PM PST by MurrietaMadman
[ Post Reply | Private Reply | To 1 | View Replies]

To: MurrietaMadman
The man in the middle is Soupy Sales.

Don't ask, you don't want to know... :-)

4 posted on 11/23/2015 10:28:01 PM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 3 | View Replies]

To: dayglored

I hate Dell, and not because they wouldn’t hire me 10 years ago. They’re sloppy, their bloatware sucks, they have abysmal customer support, and their enterprise platforms are poorly designed. Now this?

If I’m not mistaken, one could very easily go into their Windows certificate store and purge the root certificate store of only the most essential root certificates. I do that at least once a year to make sure none of the programs on my system are trying to sneak something past me. Microsoft even publishes a root certificate update (quarterly, I believe).


5 posted on 11/24/2015 4:16:43 AM PST by rarestia (It's time to water the Tree of Liberty.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

bfl


6 posted on 11/24/2015 4:25:41 AM PST by ImNotLying
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored
Wow, that is bad! What a n00b mistake! Very embarrassing…
7 posted on 11/24/2015 4:46:00 AM PST by cartan
[ Post Reply | Private Reply | To 1 | View Replies]

To: cartan

This is a temporary issue, it seems.

They goofed. They’ll get this straightened out.

I’m for Dell on this.

But I wouldn’t buy one until this is resolved.


8 posted on 11/24/2015 4:48:33 AM PST by Cringing Negativism Network (http://www.census.gov/foreign-trade/balance/c5700.html)
[ Post Reply | Private Reply | To 7 | View Replies]

To: dayglored

White Fang? That You?


9 posted on 11/24/2015 5:23:52 AM PST by HughHefner
[ Post Reply | Private Reply | To 4 | View Replies]

To: dayglored

FYI

Majorgeeks.com has an eDellRoot Certificate Fix, apparently released by Dell:

http://www.majorgeeks.com/files/details/edellroot_certificate_fix.html


10 posted on 11/24/2015 6:52:09 AM PST by TomGuy
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

Weren’t we just talking about a similar situation with Lenovo machines a few months ago? This is almost the equivalent of taping your password to the monitor - you know - for convenience ;’)


11 posted on 11/24/2015 7:50:46 AM PST by rockrr (Everything is different now...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: HughHefner
> White Fang? That You?

Well, it sure as heck ain't Black Tooth!

12 posted on 11/24/2015 9:35:07 AM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 9 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson