Dell Pulls A Lenovo And Makes Their Computers Vulnerable To Attack [UPDATED]

Clearly Dell was not paying attention the stupidity that Lenovo has been caught doing over and over again. I say that because Dell has fessed up to putting on a piece of software on their laptops that leaves them open to attack. What’s worse is that the software in question has been there since August 2015. Here’s what security researcher Brian Krebs had to say on this:

At issue is a root certificate installed on newer Dell computers that also includes the private cryptographic key for that certificate. Clever attackers can use this key from Dell to sign phony browser security certificates for any HTTPS-protected site.

Translation: A malicious hacker could exploit this flaw on open, public networks (think WiFi hotspots, coffee shops, airports) to impersonate any Web site to a Dell user, and to quietly intercept, read and modify all of a vulnerable Dell system’s Web traffic.

Lovely. That really makes on run out to buy a Dell laptop. To their credit, they are going to fix this. But one has to wonder why anyone at Dell thought that including the private and public keys of a certificate installed on laptops that they sell was ever a good idea.

UPDATE: The news has just broke that two more self signed certificates have been found on Dell laptops. It isn’t as bad as Dells self signed certificate, but it shows that Dell’s QA is clearly asleep at the switch.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading