Page 1 of 1
Dell ships laptops with security hole since last August
Posted: 24 Nov 2015, 03:06
by elecplus
Posted: 24 Nov 2015, 08:02
by Halvar
Yes, it's pretty outrageous what they did there, installing a root certificate and also installing its private key on every laptop, effectively opening up the computer to mitm-attacks for all domains.
Heise.de posted a way to check if the cert is installed on your pc and a how-to for removal, but it's in German:
http://www.heise.de/newsticker/meldung/ ... 15015.html
Posted: 24 Nov 2015, 12:01
by andrewjoy
Not again! Lenovo did this as well at one point. Another good example of why you NEVER EVER use the stock build that comes with your computer. And as 90% of people dont game on a laptop , just use linux.
Posted: 24 Nov 2015, 12:10
by Muirium
Open the packaging. Hook up the power. Wipe the hard drive. Standard new PC buying experience!
Of course, like Linux, almost nobody does it. Which is why bundled crapware exists. You know, on Windows. Can't say I ever encounter it myself…
Posted: 24 Nov 2015, 12:33
by Halvar
Posted: 24 Nov 2015, 12:58
by Muirium
I've got my ancient PowerBook out for the day, so like 7bit all I see is a placeholder where the video should go. I'll imagine something sarcastic!
Posted: 24 Nov 2015, 14:46
by andrewjoy
Its a video about how an iMac is faster to set up than a HP Pavilion.
Posted: 24 Nov 2015, 14:49
by DanielT
No, it's just the classic "oh how nice Mac is and how complicated is to set-up a normal computer... " After having my first contact with a MacPro at work and using it for the last month or so I can say it's not for me, sure it's nice and works and oh how long the battery lasts but I would never trade my T400 for a Mac, I like to be able to open my computer and tinker and whatnot

and Linux is better

Posted: 24 Nov 2015, 14:51
by derzemel
Muirium wrote: Open the packaging. Hook up the power. Wipe the hard drive. Standard new PC buying experience!
If Dell did it the same way as Lenovo, by installing the crapware from the part of the BIOS reserved for custom drivers, then it cannot be removed by wiping/changing the hdd
Posted: 24 Nov 2015, 15:05
by andrewjoy
On modern systems that will still be on the EFI partition of the hard disk , as far as i am aware there are no custom drivers in the EFI.
Posted: 24 Nov 2015, 15:27
by bhtooefr
andrewjoy: One of Lenovo's
scandals (not Superfish) was with pushing the Lenovo Service Engine through the mechanisms typically used by anti-theft software to embed into Windows - on Windows 7 and older, hijacking autochk.exe after the OS is installed, and on Windows 8 and newer, using the Windows Platform Binary Table (which was Microsoft's mechanism to stop anti-theft software from pulling crap like modifying the filesystem behind their back, and let Windows handle the installation of it).
I'm not touching my own employer's issues with certificates with a ten foot pole, though, at least not on a public thread (other than
that they've reported that they've now resolved it) - in any case, I've got nothing to do with any of that. (And, my opinions on here are my own, I'm definitely not compensated by Dell for posting on here, etc., etc..)
Posted: 24 Nov 2015, 15:54
by vivalarevolución
Please don't ask me to put forth minimal effort to set up Linux on my computer, that's too much.
Posted: 24 Nov 2015, 15:56
by andrewjoy
That is terrible, not only that the feature exists , but that they took advantage of it.