Dell Confirms Loophole on Its PCs Can Let Hackers Snoop on You

Advertisement
By Manish Singh | Updated: 24 November 2015 14:45 IST

Leading PC manufacturer Dell is being accused of shipping its desktops and laptops with a self-signed digital certificate dubbed eDellRoot that could be exploited by hackers to leave the system vulnerable to man-in-the-middle attacks, letting them snoop on Internet traffic. Several users have confirmed on forums and social media networks that their Dell computers has the eDellRoot certificate preinstalled. The US-based company has acknowledged a security vulnerability in the said certificate.

"The recent situation raised is related to an on-the-box support certificate intended to provide a better, faster and easier customer support experience," Dell said in a statement to Reuters. "Unfortunately, the certificate introduced an unintended security vulnerability."

Advertisement

Dell declined to say how many PCs or which models were affected. A Dell spokeswoman said the software began getting installed on laptops in August. Dell added PCs shipping would not contain the bug in the future.

The company added it would provide customers with instructions to permanently remove the certificate by email and on its support website.

Advertisement

In the meanwhile, you can visit this website to check if your Dell computer is vulnerable. (Update: the company has issued instructions to remove the fraudulent certificate.)

The discovery comes nearly six months after Lenovo was caught pre-installing its own, self-signed root certificates on its machines. The certificates were provided by an adware advertising company called Superfish. Lenovo has since been caught in another such practice, where it was found to force installing suspicious programs on startup.

Advertisement

As for Dell, the digital certificate in question comes preinstalled as a root certificate and contains its private key. An attacker can exploit the vulnerability and use the key to sign certificates for other non-HTTPs websites. This could allow an attacker to decrypt encrypted Web browser traffic without a victim noticing anything. The vulnerability could allow an attacker to get fake Web pages pretend to be any other site, as Web browsers installed on a victim's Dell machine will trust any certificate issued by eDellRoot. For instance, a fake webpage can tap on eDellRoot-signed SSL certificate to pretend it's your banking website.

(Also see: Lenovo Covertly Downloading, Installing Software on Its Windows PCs: Reports)

"Dell seems to be repeating the Lenovo Superfish fiasco. With the pre-installed certificate and its private key, any website can claim to be any other site and Dell computers wouldn't be able to tell the difference," Mikko Hypponen, Chief Research Officer at F-Secure told Gadgets 360 in a statement. "Bad stuff," he added.

Advertisement

As researchers point out, an attacker could get access to a victim's username, passwords, session cookies, and other sensitive information. The certificate can also be used to sign malicious apps and the computer wouldn't be able to tell a difference. Users are also reporting that it seems impossible to get rid of the digital certificate as even if you delete it, it pops-up right back after a reboot.

"'You have a private key that corresponds to this certificate'," wrote Joe Nord, a security researcher. "This is getting very fishy! As a user computer, I should NEVER have a private key that corresponds to a root CA. Only the certificate issuing computer should have a private key and that computer should be ... very well protected!"

Nord confirmed that his computer was vulnerable to attacks after visiting an HTTPS test website, which if visited from a Web browser on an unaffected computer will flag vulnerabilities in the webpage. Nord noted that Google's Chrome, Microsoft's Edge and Internet Explorer showed no warnings. Mozilla Firefox, however, alerted trust issues with the certificate on the said website.

Written with inputs from AFP

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. OTT Releases This Week (April 13 - April 19): Toaster, Matka King, Assi, and More
  2. Vivo X300 FE Could Be Available in These Two Storage Options in India
  3. Vivo X300 Ultra, Vivo X300 FE Confirmed to Launch in India Soon
  4. Some Samsung Galaxy S27 Series Models May Get This Major Storage Upgrade
  5. Amazfit Cheetah 2 Pro With 1.32-Inch AMOLED Screen Launched: See Price
  6. Google Is Reportedly Working on This Notification Feature on Android 17
  7. DJI Osmo Pocket 4 Debuts With 1-inch CMOS Sensor, Improved Stabilisation
  1. Scientists Just Created the Largest 3D Map of the Universe Ever to Study Dark Energy
  2. Honor 600 Pro and Honor 600 Key Specifications, Features Revealed via Official Listing
  3. Ethereum NFT Platform Shuts Down After Blacklove Sale Falls Through
  4. Vivo X300 FE Storage Options Leaked Alongside Live Image With Telephoto Extender Kit
  5. Indian Smartphone Shipments Dropped to Six-Year Low in Q1 2026 as Vivo Topped Market, Nothing Led Growth: Counterpoint
  6. Canva Introduces Canva AI 2.0, Brings Agentic Capabilities and Memory to Perform Design Tasks
  7. MediaTek Dimensity 9600 Pro Leak Suggests 5GHz Clock Speed, High Benchmark Scores
  8. Oppo Find X9s Pro Key Specifications Surface Online as Launch Date Draws Closer
  9. Russian-Based Crypto Exchange Grinex Halts Operation After $14 Million Hack
  10. Assassin's Creed: Black Flag Resynced Will Reportedly Release in July, Reveal Set for Next Week
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.