Clearly Dell was not paying attention the stupidity that Lenovo has been caught doing over and over again. I say that because Dell has fessed up to putting on a piece of software on their laptops that leaves them open to attack. What’s worse is that the software in question has been there since August 2015. Here’s what security researcher Brian Krebs had to say on this:
At issue is a root certificate installed on newer Dell computers that also includes the private cryptographic key for that certificate. Clever attackers can use this key from Dell to sign phony browser security certificates for any HTTPS-protected site.
Translation: A malicious hacker could exploit this flaw on open, public networks (think WiFi hotspots, coffee shops, airports) to impersonate any Web site to a Dell user, and to quietly intercept, read and modify all of a vulnerable Dell system’s Web traffic.
Lovely. That really makes on run out to buy a Dell laptop. To their credit, they are going to fix this. But one has to wonder why anyone at Dell thought that including the private and public keys of a certificate installed on laptops that they sell was ever a good idea.
UPDATE: The news has just broke that two more self signed certificates have been found on Dell laptops. It isn’t as bad as Dells self signed certificate, but it shows that Dell’s QA is clearly asleep at the switch.
Related
This entry was posted on November 24, 2015 at 11:39 am and is filed under Commentary with tags Dell. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Dell Pulls A Lenovo And Makes Their Computers Vulnerable To Attack [UPDATED]
Clearly Dell was not paying attention the stupidity that Lenovo has been caught doing over and over again. I say that because Dell has fessed up to putting on a piece of software on their laptops that leaves them open to attack. What’s worse is that the software in question has been there since August 2015. Here’s what security researcher Brian Krebs had to say on this:
At issue is a root certificate installed on newer Dell computers that also includes the private cryptographic key for that certificate. Clever attackers can use this key from Dell to sign phony browser security certificates for any HTTPS-protected site.
Translation: A malicious hacker could exploit this flaw on open, public networks (think WiFi hotspots, coffee shops, airports) to impersonate any Web site to a Dell user, and to quietly intercept, read and modify all of a vulnerable Dell system’s Web traffic.
Lovely. That really makes on run out to buy a Dell laptop. To their credit, they are going to fix this. But one has to wonder why anyone at Dell thought that including the private and public keys of a certificate installed on laptops that they sell was ever a good idea.
UPDATE: The news has just broke that two more self signed certificates have been found on Dell laptops. It isn’t as bad as Dells self signed certificate, but it shows that Dell’s QA is clearly asleep at the switch.
Share this:
Like this:
Related
This entry was posted on November 24, 2015 at 11:39 am and is filed under Commentary with tags Dell. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.