Dell does a Superfish, ships PCs with self-signed root certificates
arstechnica.com
arstechnica.com
The only to win this game, both for producers and consumers, is not to play. Don't let a company that sells shitty PCs install software for you.
If I had the time, I would install Windows from scratch on each and every machine anyway, just to get rid of the insane amounts of, uh, stuff that typically come preinstalled on machines these days.
But the only cases where I could justify the effort were machines for our automation people, because those came with Windows 8/8.1 preinstalled, and currently, Siemens only supports their Simatic/WinCC software on Windows 7.
Sigh Does anybody know of an easy way to remove this certificate?
I seriously would like to know what's in it for Dell. I mean, creating the certificate and putting it into their install images meant additional work.
Large companies make ten thousand software changes per year, a few of them are bound to be perceived as dangerous and nefarious. For me, the stasistical view is more useful than the attempt to find motive.
I don't blame them. 99% of their changes are benign. but I don't suffer the illusion that they're consciously working in my interest. Asking, "why did they do this?" implies that that this action is different from past ones. I group all those actions together as "actions of a large corporation."
edit: phrasing.