Resend my activation email : Register : Log in 
BCF: Bike Chat Forums


Dell does a Lenovo

Reply to topic
Bike Chat Forums Index -> Dear Auntie BCF...
View previous topic : View next topic  
Author Message

ScaredyCat
World Chat Champion



Joined: 19 May 2012
Karma :

PostPosted: 09:31 - 24 Nov 2015    Post subject: Dell does a Lenovo Reply with quote

Quote:
affected Dell computers are being shipped with a pre-installed trusted root certificate - called eDellRoot - that can intercept HTTPS encrypted traffic for each and every website you visit.


https://dl.dropboxusercontent.com/u/188253/dell-mmc.png

Oh... and the private key of course...

https://dl.dropboxusercontent.com/u/188253/certgeneral.png
____________________
Honda CBF125 ➝ NC700X
Honda CBF125 ↳ Speed Triple
 Back to top
View user's profile Send private message You must be logged in to rate posts

DrSnoosnoo
World Chat Champion



Joined: 28 Mar 2012
Karma :

PostPosted: 09:38 - 24 Nov 2015    Post subject: Reply with quote

I r compooter noob. What does this mean? Is it a snooping device?
____________________
I'm Sam; Northern, Ginger, Lover
Did have: '95 ZZR600 '83 CG125 '97 ZZR1100 '15 Hypermotard 821 SP Do Have: '10 ZX10R
 Back to top
View user's profile Send private message Send e-mail You must be logged in to rate posts

DrDonnyBrago
World Chat Champion



Joined: 03 Jan 2010
Karma :

PostPosted: 09:47 - 24 Nov 2015    Post subject: Reply with quote

https://en.community.dell.com/dell-blogs/direct2dell/b/direct2dell/archive/2015/11/23/response-to-concerns-regarding-edellroot-certificate
 Back to top
View user's profile Send private message You must be logged in to rate posts

ScaredyCat
World Chat Champion



Joined: 19 May 2012
Karma :

PostPosted: 10:21 - 24 Nov 2015    Post subject: Reply with quote

snoosnoo wrote:
I r compooter noob. What does this mean? Is it a snooping device?


It means anyone who decided to attack/target a user can create an https certificate for ANY website and your browser will accept it as genuine and not warn you.
____________________
Honda CBF125 ➝ NC700X
Honda CBF125 ↳ Speed Triple
 Back to top
View user's profile Send private message You must be logged in to rate posts

J.M.
World Chat Champion



Joined: 27 Mar 2011
Karma :

PostPosted: 22:52 - 24 Nov 2015    Post subject: Reply with quote

ScaredyCat wrote:
snoosnoo wrote:
I r compooter noob. What does this mean? Is it a snooping device?


It means anyone who decided to attack/target a user can create an https certificate for ANY website and your browser will accept it as genuine and not warn you.


Or in Laymans terms, I can watch and see anything you do via your web browser if we're connected to the same WiFi.
____________________
2004 R1 & 2018 XSR900
 Back to top
View user's profile Send private message You must be logged in to rate posts

Polarbear
Super Spammer



Joined: 24 Feb 2007
Karma :

PostPosted: 00:33 - 25 Nov 2015    Post subject: Reply with quote

Which way round?

If I have a Dell I can see what others do or if I have a Dell, others can see what I do?
____________________
Triumph Trophy Launch Edition
 Back to top
View user's profile Send private message Send e-mail You must be logged in to rate posts

J.M.
World Chat Champion



Joined: 27 Mar 2011
Karma :

PostPosted: 15:09 - 25 Nov 2015    Post subject: Reply with quote

I haven't fully read in to it, so I can't comment for certain.

A certificate is created by a signing body and added to a computer. A website will be signed by one of the signing bodies in order to use HTTPS.

When you go on a HTTPS website, your computer verifies the website's certificate by using the signing body's certificate that is on your computer. If you don't have the signing body's certificate, you will get an error. If the website's certificate is wrong or tampered with, you will get an error.

This Dell certificate is another signing body certificate. It can be used to create valid certificates for websites. This means that whoever owns the dell certificate is able to create a certificate for any HTTPS website.

This means that person can sit in the middle of a connection between say you and the bank, and your computer would have no idea, because they can present to you a valid certificate because the Dell certificate verifies it.

These certificates by the signing body work in two parts:
- public key
- private key

The signing body will sign the certificate to the website with their private key. The public key is on your computer and you decrypt the message using their public key to verify it. (Note this is the opposite way around than encrypting a message).

ScaredyCat's screenshot clearly shows that the private key for the signing certificate is on each computer. This means that anybody can create a certificate for a website and the dell computer will accept it.

This is assuming that Dell hasn't generated a unique key for each system produced, which I would find highly unlikely.

Even if the company didn't have bad intentions, as their official comment states, this is exactly the reason why companies need to hire people that actually understand the security implications of their actions, rather than hiring just programmers.

tl;dr if you're smart, you'll probably be able to see what others do. Others will be able to see what you do too (unless you remove the certificate).
____________________
2004 R1 & 2018 XSR900
 Back to top
View user's profile Send private message You must be logged in to rate posts

CaNsA
Super Spammer



Joined: 02 Jan 2008
Karma :

PostPosted: 15:12 - 25 Nov 2015    Post subject: Reply with quote

But wait, there's more.

https://www.theregister.co.uk/2015/11/25/dsdtestprovider/
 Back to top
View user's profile Send private message You must be logged in to rate posts
Old Thread Alert!

The last post was made 10 years, 62 days ago. Instead of replying here, would creating a new thread be more useful?
  Display posts from previous:   
This page may contain affiliate links, which means we may earn a small commission if a visitor clicks through and makes a purchase. By clicking on an affiliate link, you accept that third-party cookies will be set.

Post new topic   Reply to topic    Bike Chat Forums Index -> Dear Auntie BCF... All times are GMT
Page 1 of 1

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum

Read the Terms of Use! - Powered by phpBB © phpBB Group
 

Debug Mode: ON - Server: birks (www) - Page Generation Time: 0.06 Sec - Server Load: 0.74 - MySQL Queries: 14 - Page Size: 58.07 Kb