Jump to content

Dell has a Superfish-like certificate on their machines

Techdude154

A user on Reddit has found a certificate included on his recent Dell XPS 15 similar to the Superfish certificate used by Lenovo this year.

 

Here is the reddit thread:

https://www.reddit.com/r/technology/comments/3twmfv/dell_ships_laptops_with_rogue_root_ca_exactly/

 

 

I got a shiny new XPS 15 laptop from Dell, and while attempting to troubleshoot a problem, I discovered that it came pre-loaded with a self-signed root CA by the name of eDellRoot

 

 

DBromxS.png

 

An article was written about this as well from TechWeekeurope who have confirmed with a product manager from Citrix that the certificate was found on his Inspiron 5000 series:

 

 

These claims were backed up by Joe Nord, a product manager for Citrix, who said he found the same certificate on a Dell Inspiron 5000 series laptop bought in October while setting up his computer and said his thoughts immediately turned to superfish.

 

 

TechWeekeurope has attempted to contact dell and will update when they get a response

 

TechWeekEurope has contacted Dell and will update this article if we receive a response. Hicks did speak to Dell on Twitter and was told it was a “trusted” certificate, although later correspondence suggested Dell was speaking to its product team to find out why the certificate was present.

 

 

 

Here is the article:

http://www.techweekeurope.co.uk/security/firewall/superfish-like-rogue-certificates-found-pre-installed-dell-pcs-181034

 

It's unfortunate to see Dell go the way of Lenovo and install the certificate. Nobody actually knows what this one does yet, at least with Lenovo we saw it inject ads. We'll have to see what happens when dell responds. Personally I'm probably not going to buy any product from them again, which is something I would not like to do because I really like them.

 

*edit:

Here's another article from arstechnica

 

http://arstechnica.com/security/2015/11/dell-does-superfish-ships-pcs-with-self-signed-root-certificates/

Link to comment
Share on other sites

Link to post
Share on other sites

Im not buying this at all... Its a self signed certificate that has very limited access to do anything at all. Id guess that the only reason its there is to self sign DELL bloat-ware for automatic upgrades (to make sure its not been tampered with).

Intel I9-9900k (5Ghz) Asus ROG Maximus XI Formula | Corsair Vengeance 16GB DDR4-4133mhz | ASUS ROG Strix 2080Ti | EVGA Supernova G2 1050w 80+Gold | Samsung 950 Pro M.2 (512GB) + (1TB) | Full EK custom water loop |IN-WIN S-Frame (No. 263/500)

Link to comment
Share on other sites

Link to post
Share on other sites

Can we sue them for false advertising by omission?

Oh wait, then we would have done that to Lenovo...

Link to comment
Share on other sites

Link to post
Share on other sites

Uh oh Dell. I'm actually surprised things hasn't been suspected from other pc companies after the shitstorm that Lenovo did.

ROG X570-F Strix AMD R9 5900X | EK Elite 360 | EVGA 3080 FTW3 Ultra | G.Skill Trident Z Neo 64gb | Samsung 980 PRO 
ROG Strix XG349C Corsair 4000 | Bose C5 | ROG Swift PG279Q

Logitech G810 Orion Sennheiser HD 518 |  Logitech 502 Hero

 

Link to comment
Share on other sites

Link to post
Share on other sites

FFS, WHY THE FUCK WOULD YOU COMPRISES YOUR CLIENTS WITH THAT SHIT, THIS IS HOW YOU GET PEOPLE TO NOT BUY YOUR FUCKING PRODUCT, NOR COMEBACK AFTERWARDS...

 

and then they fucking wonder why Apple macs still grow despite everyone selling less, jesus fuu- christ.

 

/rant

 

worst part for me is that the new XPS 15 is such a badass laptop ;_;

this is one of the greatest thing that has happened to me recently, and it happened on this forum, those involved have my eternal gratitude http://linustechtips.com/main/topic/198850-update-alex-got-his-moto-g2-lets-get-a-moto-g-for-alexgoeshigh-unofficial/ :')

i use to have the second best link in the world here, but it died ;_; its a 404 now but it will always be here

 

Link to comment
Share on other sites

Link to post
Share on other sites

A certificate in and of itself doesn't seem that harmful to me, I'm not sure I understand the problem.

I cannot be held responsible for any bad advice given.

I've no idea why the world is afraid of 3D-printed guns when clearly 3D-printed crossbows would be more practical for now.

My rig: The StealthRay. Plans for a newer, better version of its mufflers are already being made.

Link to comment
Share on other sites

Link to post
Share on other sites

Lenovo started it, DELL followed .. wonder where HP stands  :lol:

Checking my HP now for eHPRoot... Nope don't have, got nothing with HP in it. Then it's obvious I've done a clean install without the bloat crap.

Intel Xeon E5 1650 v3 @ 3.5GHz 6C:12T / CM212 Evo / Asus X99 Deluxe / 16GB (4x4GB) DDR4 3000 Trident-Z / Samsung 850 Pro 256GB / Intel 335 240GB / WD Red 2 & 3TB / Antec 850w / RTX 2070 / Win10 Pro x64

HP Envy X360 15: Intel Core i5 8250U @ 1.6GHz 4C:8T / 8GB DDR4 / Intel UHD620 + Nvidia GeForce MX150 4GB / Intel 120GB SSD / Win10 Pro x64

 

HP Envy x360 BP series Intel 8th gen

AMD ThreadRipper 2!

5820K & 6800K 3-way SLI mobo support list

 

Link to comment
Share on other sites

Link to post
Share on other sites

It is just a certificate used for encryption... It is not at all like the Spyware that was found on Lenovo laptops.

Edit: haha they included their private key with the cert? It's a massive fuckup that results in a big security hole, but it's still nothing like what Lenovo did.

Link to comment
Share on other sites

Link to post
Share on other sites

It is just a certificate used for encryption... It is not at all like the Spyware that was found on Lenovo laptops.

 

Until more info is available this is my current stance on it.

 

 

 

I only really buy their monitors anyways.

Someone told Luke and Linus at CES 2017 to "Unban the legend known as Jerakl" and that's about all I've got going for me. (It didn't work)

 

Link to comment
Share on other sites

Link to post
Share on other sites

Ummm...Reformat your crappy Dell(no offense, Dell owners.) disk, then installing fresh (real one) Windows OS in.... There's no smell superfish and bloatware bullshit.  Use common sense.

CPU:AMD Ryzen 5 5600 3.5 GHz Processor | CPU Air Cooler:Thermalright Assassin X 120 Refined SE | Motherboard:MSI B450M GAMING PLUS MATX AM4

Memory:G.Skill Ripjaws V Series 32GB (2x16GB)  DDR4-3200 | GPU:PowerColor Fighter Radeon RX 7600 8 GB Video Card

Storage #1:Silicon Power A55 512GB SSD (OS driver) | Storage #2: Silicon Power A60 1TB M.2-2280 PCIe 3.0 X4 NVMe (Anything else)

Case:Cooler Master MasterBox Q300L | Case Fan: 3x Thermalright TL-C12C (2x intake fans, 1x exhaust fan)

Power Supply:Corsair CXM (2015) 450W Bronze 80 Plus |OS:MS Windows10 (64-bit) | Monitor: ASUS VG275 27” 1080p 75 Hz FreeSync

Link to comment
Share on other sites

Link to post
Share on other sites

i don't get why people get all pissed about this and lenovo but not at microsoft...

One day I will be able to play Monster Hunter Frontier in French/Italian/English on my PC, it's just a matter of time... 4 5 6 7 8 9 years later: It's finally coming!!!

Phones: iPhone 4S/SE | LG V10 | Lumia 920 | Samsung S24 Ultra

Laptops: Macbook Pro 15" (mid-2012) | Compaq Presario V6000

Other: Steam Deck

<>EVs are bad, they kill the planet and remove freedoms too some/<>

Link to comment
Share on other sites

Link to post
Share on other sites

Until more info is available this is my current stance on it.

 

 

 

I only really buy their monitors anyways.

Yeah I'm still going to buy their monitors, but a little sketch on their laptops/desktops now.

 

i don't get why people get all pissed about this and lenovo but not at microsoft...

Explain? Why should we be pissed at Microsoft? Cause I've been seeing MS hate 100% of the time for the past 5 months since W10 has been released.

Link to comment
Share on other sites

Link to post
Share on other sites

Explain? Why should we be pissed at Microsoft? Cause I've been seeing MS hate 100% of the time for the past 5 months since W10 has been released.

 

cause it's an adware

One day I will be able to play Monster Hunter Frontier in French/Italian/English on my PC, it's just a matter of time... 4 5 6 7 8 9 years later: It's finally coming!!!

Phones: iPhone 4S/SE | LG V10 | Lumia 920 | Samsung S24 Ultra

Laptops: Macbook Pro 15" (mid-2012) | Compaq Presario V6000

Other: Steam Deck

<>EVs are bad, they kill the planet and remove freedoms too some/<>

Link to comment
Share on other sites

Link to post
Share on other sites

cause it's an adware

It isn't.

 

Lenovo was adware (injected ads into websites you visited).

This Dell thing is a security issue that seems like a very big oversight (potentially allows Trojan horses to appear like genuine HP software for HP users).

Windows 10 is spyware (collects information about users without their full knowledge and consent).

Link to comment
Share on other sites

Link to post
Share on other sites

It isn't.

 

Lenovo was adware (injected ads into websites you visited).

This Dell thing is a security issue that seems like a very big oversight (potentially allows Trojan horses to appear like genuine HP software for HP users).

Windows 10 is spyware (collects information about users without their full knowledge and consent).

okay, interpreted this case to be similar to lenovo's superfish

but Win10 does serve you ads based on that data collection too

One day I will be able to play Monster Hunter Frontier in French/Italian/English on my PC, it's just a matter of time... 4 5 6 7 8 9 years later: It's finally coming!!!

Phones: iPhone 4S/SE | LG V10 | Lumia 920 | Samsung S24 Ultra

Laptops: Macbook Pro 15" (mid-2012) | Compaq Presario V6000

Other: Steam Deck

<>EVs are bad, they kill the planet and remove freedoms too some/<>

Link to comment
Share on other sites

Link to post
Share on other sites

okay, interpreted this case to be similar to lenovo's superfish

but Win10 does serve you ads based on that data collection too

What ads?

Lets all ripperoni in pepperoni

Link to comment
Share on other sites

Link to post
Share on other sites

What ads?

the ones you'll see on the start menu, at bing, at outlook, inside apps that use MS's universal ad client, etc etc

One day I will be able to play Monster Hunter Frontier in French/Italian/English on my PC, it's just a matter of time... 4 5 6 7 8 9 years later: It's finally coming!!!

Phones: iPhone 4S/SE | LG V10 | Lumia 920 | Samsung S24 Ultra

Laptops: Macbook Pro 15" (mid-2012) | Compaq Presario V6000

Other: Steam Deck

<>EVs are bad, they kill the planet and remove freedoms too some/<>

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×