Jump to content

Recommended Posts

Posted

Link: Dell acknowledges security hole in new laptops | Reuters

 

..."The recent situation raised is related to an on-the-box support certificate intended to provide a better, faster and easier customer support experience,” Dell said in a statement to Reuters. “Unfortunately, the certificate introduced an unintended security vulnerability.”

 

Dell declined to say how many computers or which specific models are affected. The software began getting installed on laptops in August, according to a spokeswoman. The company also said future systems would not contain the bug...

Posted

Link: eDellRoot certificate removal instructions [TheWindowsClub.COM]

 

...This post will show you how to completely remove the rogue eDellRoot certificate from your Dell laptop or desktop computer, manually or using an automatic fix from Dell...

 

...Dell has also released a fix that will automatically remove eDellRoot from your computer. You can download the automatic removal patch eDellRootCertFix.exe from Dell and use it.
[Note: The download will start upon clicking this link]
Posted

From the horse's mouth... :)

 

Response to Concerns Regarding eDellroot Certificate

 

Today we became aware that a certificate (eDellRoot), installed by our Dell Foundation Services application on our PCs, unintentionally introduced a security vulnerability. The certificate was implemented as part of a support tool and intended to make it faster and easier for our customers to service their system. Customer security and privacy is a top concern and priority for Dell; we deeply regret that this has happened and are taking steps to address it.

 

The certificate is not malware or adware. Rather, it was intended to provide the system service tag to Dell online support allowing us to quickly identify the computer model, making it easier and faster to service our customers. This certificate is not being used to collect personal customer information. It’s also important to note that the certificate will not reinstall itself once it is properly removed using the recommended Dell process.

 

We have posted instructions to permanently remove the certificate from your system here. We will also push a software update starting on November 24 that will check for the certificate, and if detected remove it. Commercial customers who reimaged their systems without Dell Foundation Services are not affected by this issue. Additionally, the certificate will be removed from all Dell systems moving forward.

 

If the affected computers are connected to a domain you can simply revoke the certificate via Group Policy rather than use Dell's tool. A copy or the certificate is attached. See the link below for further details.

 

http://happysccm.com/revoke-dell-cert

 

http://vgy.me/YA5Y47.png

eDellRoot.zip

Posted

PCs running Dell support app can be uniquely ID’d by snoops and scammers

 

Websites can surreptitiously acquire the ID of just about any Dell machine that's running Dell Foundation Services, an official Dell application designed to make it easier for customers to get technical support. As this proof-of-concept site demonstrates, the exploit works relatively quickly and reliably. While it's transparent about what it's doing, there's nothing stopping other sites from running the ID-scraping code in the background so users have no idea they're being tracked.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...