The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.
Problems? See this thread at archive.org.

    Dell Acknowledges HTTPS Certificate Exploit - Provides Removal Tool

    Discussion in 'Dell XPS and Studio XPS' started by Chris9446, Nov 24, 2015.

  1. Chris9446

    Chris9446 Notebook Consultant

    Reputations:
    0
    Messages:
    145
    Likes Received:
    11
    Trophy Points:
    41
    http://arstechnica.com/security/201...tps-certificate-fiasco-provides-removal-tool/

    "The certificate is not malware or adware. Rather, it was intended to provide the system service tag to Dell online support allowing us to quickly identify the computer model, making it easier and faster to service our customers. This certificate is not being used to collect personal customer information. It’s also important to note that the certificate will not reinstall itself once it is properly removed using the recommended Dell process."​

    Removal tool is here
    https://dellupdater.dell.com/Downloads/APP009/eDellRootCertFix.exe
     
  2. ghtop

    ghtop Notebook Consultant

    Reputations:
    4
    Messages:
    127
    Likes Received:
    24
    Trophy Points:
    31
    Sadly there's a second root certificate problem that hasn't yet been fixed, and has only just been acknowledged by Dell:

    http://www.computerworld.com/articl...ngerous-dell-root-certificate-discovered.html

    Installed in this case by Dell System Detect (which was already the subject of another security scare in April). Worryingly, it doesn't seem like the right hand knows what the left is doing at Dell. They just need to pull all of their code at this point and do a proper security audit.

    After firing the current security team, of course.

    Edit: Oh, and just to rub salt into the wound, here's another issue with Dell Foundation Services: http://arstechnica.com/security/201...p-can-be-uniquely-idd-by-snoops-and-scammers/
     
    Last edited: Nov 24, 2015
  3. OXINARF

    OXINARF Notebook Enthusiast

    Reputations:
    2
    Messages:
    20
    Likes Received:
    3
    Trophy Points:
    16
  4. MttThms

    MttThms Notebook Enthusiast

    Reputations:
    0
    Messages:
    18
    Likes Received:
    3
    Trophy Points:
    6
    Just got mine in the mail. Will a fresh install of WIndows 10 take care of this stuff or do I actually have to dig into those solutions?
     
  5. Raidriar

    Raidriar ლ(ಠ益ಠლ)

    Reputations:
    1,708
    Messages:
    5,820
    Likes Received:
    4,311
    Trophy Points:
    431
    Fresh install and don't install any Dell software.
     
  6. MttThms

    MttThms Notebook Enthusiast

    Reputations:
    0
    Messages:
    18
    Likes Received:
    3
    Trophy Points:
    6
    Cool. Can't wait to break this thing in over the holiday weekend.