Response to Concerns Regarding eDellroot Certificate
en.community.dell.com
en.community.dell.com
That's something a lot of companies could learn from. But besides that the whole reason why they did it seems a bit thin, as if it needs a root certificate to get to a device tag.
"Dell has a publicly reachable security team. They just didn't answer when I contacted them about the eDellRoot." https://twitter.com/hanno/status/668856347455324160
"I should repeat that: I contacted Dell's media team on 1st Nov and security team on 9th Nov about eDellRoot. No answer." https://twitter.com/hanno/status/668857466076180480
At first I didn't find a security contact on the Dell webpage. As I'm a journalist and as I investigated this issue to write an article (for Golem.de), the media contact was my logical next point to contact.
Around a week later without a reply I saw that hackerone had a list of security contacts for large companies and found that there was a contact address for Dell there.
There is a dell.com/security page but it lists all kinds of stuff and does not provide a security contact.
Maybe every company should have a /security page with a contact?
Or even a 'security.x.com' website as a first point of contact?
Dell should probably instruct their personnel to forward any and all mail relating to potential security issues to the right department, but at the same time I don't feel that contacting their marketing department counts as the day the issue was properly reported.
Yeah, right. There's no other way to identify the model other than loading a root certificate with the power to certify any site as any domain. They expect people to believe that? Are they incompetent or corrupt?
This oozes management trying to cover up something dirty with enough corporate speak until anyone technical gives up, leaves, or gets fired for attempting to burn the place down.
They were speaking for online support, where no support agent is available to guide the customer through finding the service tag.
I believe they had good intentions but it was very poorly executed.
I really don't understand why they would need to install a root cert to make requests from a client's machine when you already have installed an EXE on the client's machine (which can basically do anything it wants).
Can anyone think of any genuine reason why an installed executable would need a CA root cert?
It could simply be a stupid mistake, social media make stupid mistakes into big deals but they're not a new phenomenon.
Basically all the way from the idea to release, they had no person who knows what root certificates are.
As I understand it the vulnerability is that anyone who can obtain this root CA from a Dell machine can sign their encrypted traffic to appear to be trusted and secure, even if it's not, to other Dell machines with the same root CA. You can pretend to be someone you're not to those other Dell machines, but it doesn't give you a backdoor into chains of trust that don't descend from the same root CA.
I suppose this might allow you to do a MITM attack, but not decode traffic you've passively snooped. Otherwise this root CA would have just totally compromised all internet security.
Come on!
The author says right there that the certificates were "intended to make it faster and easier for our customers to service their system."
Statements completely contradicting each other.
That's a very strong statement, which a sizeable percentage of Hacker News readers could probably disprove in minutes.
Personally I but my $0.1 bet on incompetence. Which is of course bad enough but not superfish-league.