Superfish 2.0: Now Dell Is Breaking HTTPS
eff.org
eff.org
This is now gone off the main page, which is a shame.
https://hn.algolia.com/?query=dell%20points%3E10&sort=byDate...
We try to get the most substantive URL into the most prominent thread (and in fact are working on a system for users to be able to drive that) but it doesn't always work out.
To install the root key is in no way an attempt at spoofing people since it would eventually be discovered and exploited by someone else. If Dell wanted to use this pre-installed cert they would not have installed the private key. And even then it would eventually be discovered much more easily than any number of backdoor methods they could have pre-installed in the BIOS or the OS when they control the entire deployment and shipping process.
Someone did this (again without malice but clearly misguided), and it wasn't caught by any process that should have noticed or prevented these kinds of dangerous errors.
That's why I'm still running 7.
This KB sneaks in diagtrack.dll to windows 7, aka telemetry.
I have diagtrack on my work win8.1 without being prompted. I'll have to check win7 on monday. This is the first non win10 kb I've seen it mentioned in.
I have no clue how it got onto my win8.1 box.
At least for 7, I never used 8 enough to give you useful info there.
Also, it's not clear which KB snuck it onto my Win8.1.
https://answers.microsoft.com/en-us/windows/forum/all/unable...
My machine had 27 different packages/versions for this update!
A cynical person would think MS is deviously trying to hide them and prevent an end user from opting out from their data collection scheme.
I believe it will remember this preference for future installs, as in won't keep checking it each time but I've honestly never looked into it so I can't say for certain.
It's only after months of reading about it do I know enough to discern that diagtrack.dll == "telemetry".
The statement 'Which you can decline to install' makes it seem as if this is specifically flagged and you have the option of not installing it.
In reality you are describing the standard options: Automatically Update/Let Me Choose Which Updates/No Updates at all.
When users are advised to install this stuff for their own good for security purposes(Microsoft Recommended), and yet this is basically malware/a keylogger - it's pretty bad in my opinion.
http://arstechnica.com/civis/viewtopic.php?p=29497693&sid=dd...
Ars's news article: http://arstechnica.com/information-technology/2015/08/lenovo...
http://www.extremetech.com/mobile/197005-new-apple-malware-i...
https://en.wikipedia.org/wiki/Spotlight_(software)#Privacy_c...
Alfred can be setup to index folders, contents of text files, pictures, etc. and harder things like System Prefs screens too.
I myself keep Spotlight on Command Shift Space for the rare occasions when I want to take advantage of the Internet connected stuff, but keep using Alfred for everything else (less to do with privacy, more because Alfred is just quicker.)
And as a heavy spotlight user, it's infuriating to know apple is stealing my local computer searches and my location and then selling it to Microsoft.
http://www.extremetech.com/mobile/197005-new-apple-malware-i...
I didn't say a Mac was bulletproof, but the fact that Apple controls the hardware and software makes it better than the OEM's who make PCs, IMHO. No software or hardware protection will ever do better than a vigilant user, and I know that.
Please don't call names in HN comments.
> I really don't want to sound elitist, but my choice to go full Macbook and keep my custom built PC at home has never looked better.
not really name calling imho but ok, I know. It is not my normal behaviour.
Was there any reason other than plain negligence to include the private key on every laptop?
Everyone adds their crap onto the device and then wraps it up for sale, with no one having real responsibility on what actually ends up being on the device.
Given common code quality I really wonder what nasties are hidden in stuff like Embedded Controller firmware, the drivers for stuff like "special keyboard hotkeys" and similar. All places to hide a nice kernel level exploit in (or in case of the EC, full HW backdoor).
I seriously wonder how people can work for these companies. Not that they're terribly evil (b/c, after all, this rant is pretty much the definition of a First World Problem). But in that I couldn't spend the majority of my waking hours for an organization that has so little taste.
This is the distinction the person you are replying to is trying to make, because although similar to superfish, it is not quite the same.
There is no product, service, business or political cause that justifies destroying the security and integrity of the internet. This places people affected by this in an incredibly risky situation. And then rather that recall the laptops, Dell is issuing removal instructions and asking customers (many of who may be receiving the laptops second hand via personal or corporate means) to fix the problem for them.
If our law were even remotely up to date, this would result in at least a crippling fine for the company that did it.