HomeSecurityCybersecurity vulnerability in new Dell computers!

Cybersecurity vulnerability in new Dell computers!

Dell has published a guide on how to remove the online security “backdoor” it has installed on its desktops and laptops.

Dell

This proves what we already knew, that Dell is selling computers with a rather embarrassing hole in their defenses. New models from the XPS, Precision, and Inspiron lines contain a root CA certificate called eDellRoot that puts computer owners at high risk for identity theft and bank fraud.

The certificate is paired with a private key, which is a boon to attackers. For example, if a computer with this certificate connects to a malicious Wi-Fi hotspot, whoever controls the hotspot can use the certificate and the company's key to decrypt the victims' Internet traffic. This could expose users' usernames, passwords, cookies , and other sensitive personal information when they shop or bank online or connect to other HTTPS-.

The certificate cannot simply be removed, however. A plugin that is included must also be removed.

The company published a document on exactly how to properly remove it and that their next computers will not include it. A software upgrade starting today, November 24, will automatically delete it. In its announcement, it stated that they created the certificate for better, faster and easier customer support and unfortunately it showed a security vulnerability.

If you have a new Dell PC, you can check here if it contains the certificate.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS