This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

Dell ships PCs with easily cloneable root certificates

1 min read

This thread's last reply is from November 25, 2015, 4:03 PM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

In a move eerily similar to the Superfish debacle that visited Lenovo in February, Dell is shipping computers that come preinstalled with a digital certificate that makes it easy for attackers to cryptographically impersonate Google, Bank of America, and any other HTTPS-protected website.

Source: Ars Technica
Stupidity is universal it would seem. :roll:

Dell are aware of the situation ... http://en.community.dell.com/dell-blogs/direct2dell/b/direct2dell/archive/2015/11/23/response-to-concerns-regarding-edellroot-certificate ... and have now issued directions for how to remove the relevant certificate ... https://dellupdater.dell.com/Downloads/ ... tions.docx
Seems another certificate problem has been found on Dell computers ... http://www.bbc.co.uk/news/technology-34920197

"To paraphrase Oscar Wilde, to have one self-signing certificate installed could be a mistake; to have two looks like carelessness."

"The fact that there appears to be a second self-signing certificate does make you wonder what else might be lurking on the machine."