1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Dell computers shipping with potentially dangerous root certificate authority

Discussion in 'Network World' started by RSS, Nov 23, 2015.

  1. RSS

    RSS New Member Member

    At least some Dell laptops are shipping with a trusted root certificate authority pre-installed, something that those who discovered the CA are comparing to the Superfish adware installed on Lenovo machines that left them open to man-in the-middle attacks.

    Called eDellRoot, the trusted root CA comes as part of the standard software load on new Dell machines. A Reddit contributor who uses rotocowboy for a screen name says the implications could be dire. “For those that are unfamiliar with how this works,” he writes, “a network attacker could use this CA to sign his or her own fake certificates for use on real websites and an affected Dell user would be none the wiser unless they happened to check the website's certificate chain. This CA could also be used to sign code to run on people's machines, but I haven't tested this out yet.”

    To read this article in full or to leave a comment, please click here

    Continue reading...
     

Share This Page