Dell acknowledges security hole in new laptops

    Dell acknowledges security hole in new laptops

    Dell acknowledges security hole in new laptops


    Posted: 24 Nov 2015

    Major U.S. computer company Dell Inc [DI.UL] said on Monday a security hole exists in some of its recently shipped laptops that could make it easy for hackers to access users’ private data.

    A pre-installed program on some newly purchased Dell laptops that can only be removed manually by consumers makes them vulnerable to cyber intrusions that may allow hackers to read encrypted messages and redirect browser traffic to spoofs of real websites such as Google or those belonging to a bank, among other attacks.

    The recent situation raised is related to an on-the-box support certificate intended to provide a better, faster and easier customer support experience,” Dell said in a statement to Reuters. “Unfortunately, the certificate introduced an unintended security vulnerability.


    Read more: Dell acknowledges security hole in new laptops


    Today we became aware that a certificate (eDellRoot), installed by our Dell Foundation Services application on our PCs, unintentionally introduced a security vulnerability. The certificate was implemented as part of a support tool and intended to make it faster and easier for our customers to service their system. Customer security and privacy is a top concern and priority for Dell; we deeply regret that this has happened and are taking steps to address it.

    The certificate is not malware or adware. Rather, it was intended to provide the system service tag to Dell online support allowing us to quickly identify the computer model, making it easier and faster to service our customers. This certificate is not being used to collect personal customer information. It’s also important to note that the certificate will not reinstall itself once it is properly removed using the recommended Dell process.

    We have posted instructions to permanently remove the certificate from your system here. We will also push a software update starting on November 24 that will check for the certificate, and if detected remove it. Commercial customers who reimaged their systems without Dell Foundation Services are not affected by this issue. Additionally, the certificate will be removed from all Dell systems moving forward.

    Your trust is important to us and we are actively working to address this issue. We thank customers such as Hanno Böck, Joe Nord and Kevin Hicks, aka rotorcowboy, who brought this to our attention. If you ever find a potential security vulnerability in any Dell product or software, we encourage you to visit this site to contact us immediately.

    Source: Response to Concerns Regarding eDellroot Certificate
    Brink's Avatar Posted By: Brink
    24 Nov 2015


  1. Posts : 39,956
    Win 7 32, Win 7 64 Pro, Win 8.1 64 Pro, Win 10 64 Education Edition, Win 11 Pro
       #1
      My Computer


  2. Posts : 39,956
    Win 7 32, Win 7 64 Pro, Win 8.1 64 Pro, Win 10 64 Education Edition, Win 11 Pro
       #2

    The fallout from a serious security mistake made by Dell is widening, as security experts find more issues of concern.

    Researchers with Duo Security have found a second weak digital certificate in a new Dell laptop and evidence of another problematic one circulating.

    The issue started after it was discovered Dell shipped devices with a self-signed root digital certificate, eDellRoot, which is used to encrypt data traffic. But it installed the root certificate with the private encryption key included, a critical error that left many security experts aghast.
    Dell acknowledges security hole in new laptops - Windows 10 Forums
      My Computer


  3. Posts : 19
    Windows 10 Pro
       #3

    It was on my Precision M3800 that I got about 3 weeks ago. I havent gotten around to wiping and doing a clean install on it yet, but was simple and easy enough to remove for now.
      My Computer


  4. Posts : 1,546
    Windows 10 Pro x64 RS 10586.586
       #4

    Windows Defender updates definitions to remove eDellRoot


    Dell acknowledges security hole in new laptops-windows-defender-400x280.jpg

    Microsoft has come to the rescue act once again as the company updates Windows Defender to periodically search and remove eDellRoot from the user’s PC’s. Dell has already been exposed with the potential threats that its self-signed root kit ( dubbed as eDellRoot ) could bring to Dell PC owners. The private key could expose users to attackers who can easily intercept HTTPs communication between the server and user’s PC loaded with eDellRoot. All this would mean that attackers could easily decrypt, modify or spoof HTTPS websites, including banking or social media, getting access to users’ private data.
    Read more: http://news.thewindowsclub.com/windo...ellroot-80997/

    Malware Protection Center: http://www.microsoft.com/security/po...rprise=0#tab=2
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 21:43.
Find Us




Windows 10 Forums