Skip to comments.
Dell installs self-signed root certificate on laptops, endangering users' privacy
PC World ^
| 11/23/15
| Lucian Constantin
Posted on 11/23/2015 6:44:59 PM PST by markomalley
Dell laptops are coming preloaded with a self-signed root digital certificate that lets attackers spy on traffic to any secure website.
The reports first surfaced on Reddit and were soon confirmed by other users and security experts on Twitter and blogs. The root certificate, which has the power of a certificate authority on the laptops it's installed on, comes bundled with its corresponding private key, making the situation worse.
With the private key, which is now available online, anyone can generate a certificate for any website that will be trusted by browsers such as Internet Explorer and Google Chrome that use the Windows certificate store on affected laptops. Security experts have already generated proof-of-concept certificates for *.google.com and bankofamerica.com.
The certificate, which is called eDellRoot, was added to Dell consumer and commercial devices starting in August with the intention of providing better customer support, Dell said in an emailed statement: "When a PC engages with Dell online support, the certificate provides the system service tag allowing Dell online support to immediately identify the PC model, drivers, OS, hard drive, etc. making it easier and faster to service."
(Excerpt) Read more at pcworld.com ...
TOPICS: Business/Economy; Government
KEYWORDS: certificate; certificateauthority; dell; dudeyergettinadell; privacy; rootcert; selfsignedcert; windows; windowspinglist
Navigation: use the links below to view more comments.
first previous 1-20, 21-32 last
To: dayglored
Yup, good hardware. And a data center won’t get metal with pre-installed OSs.
21
posted on
11/23/2015 8:29:43 PM PST
by
Gene Eric
(Don't be a statist!)
To: UB355
My two year old dell 1500 series laptop does not have the cert Inspiron 5558. There it sits in the console like a turd in the punch bowl.
22
posted on
11/23/2015 8:34:14 PM PST
by
Stentor
("The best lack all conviction, while the worst are full of passionate intensity.")
To: driftdiver
I bought a Dell fall a year ago with Windows 8.1. Now, I have the option of converting to Win 10 at no expense & had signed up to do it, but then started reading about all the privacy issues. I use Classic Shell to make Win 8.1 look like 7 (which is what my old laptop was on before it crashed) & I've gotten used to it. I decided I wasn't going to 10 & cancelled out. Evidently, you can disable a lot of the Win 10 features that affect privacy, but it's not an easy thing to do and not all in one place. Here's the article that changed my mind about going to 10:
Everything You Need to Disable in Windows 10
23
posted on
11/23/2015 9:15:45 PM PST
by
Qiviut
To: Qiviut
Thanks for that link. Good article.
24
posted on
11/23/2015 9:39:14 PM PST
by
TChad
To: markomalley
Dell security error widens as researchers dig deeper (Earlier problem is worse than was thought) Duo Security researchers found a second weak digital certificate on a new Dell Inspiron laptop
The fallout from a serious security mistake made by Dell is widening, as security experts find more issues of concern.
Followup thread on the expanded problem:
http://www.freerepublic.com/focus/chat/3364271/posts
25
posted on
11/23/2015 9:58:56 PM PST
by
dayglored
("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
To: dayglored
That's Obama-level stupid.
26
posted on
11/23/2015 11:21:11 PM PST
by
grey_whiskers
(The opinions are solely those of the author and are subject to change without notice.)
To: grey_whiskers
>
That's Obama-level stupid. Yeah, but give the man credit for effort -- it takes a lot of hard work to consistently be that stupid.
27
posted on
11/23/2015 11:23:25 PM PST
by
dayglored
("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
To: markomalley
To: Rebelbase
29
posted on
11/24/2015 3:29:16 AM PST
by
Fresh Wind
(Falcon 105)
To: markomalley
To: markomalley; rdb3; Calvinist_Dark_Lord; JosephW; Only1choice____Freedom; amigatec; ...
31
posted on
11/24/2015 5:41:13 AM PST
by
ShadowAce
(Linux - The Ultimate Windows Service Pack)
To: markomalley
32
posted on
11/24/2015 6:52:33 AM PST
by
TomGuy
Navigation: use the links below to view more comments.
first previous 1-20, 21-32 last
Disclaimer:
Opinions posted on Free Republic are those of the individual
posters and do not necessarily represent the opinion of Free Republic or its
management. All materials posted herein are protected by copyright law and the
exemption for fair use of copyrighted works.
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson