Dell Confirms Loophole on Its PCs Can Let Hackers Snoop on You

Advertisement
By Manish Singh | Updated: 24 November 2015 14:45 IST

Leading PC manufacturer Dell is being accused of shipping its desktops and laptops with a self-signed digital certificate dubbed eDellRoot that could be exploited by hackers to leave the system vulnerable to man-in-the-middle attacks, letting them snoop on Internet traffic. Several users have confirmed on forums and social media networks that their Dell computers has the eDellRoot certificate preinstalled. The US-based company has acknowledged a security vulnerability in the said certificate.

"The recent situation raised is related to an on-the-box support certificate intended to provide a better, faster and easier customer support experience," Dell said in a statement to Reuters. "Unfortunately, the certificate introduced an unintended security vulnerability."

Dell declined to say how many PCs or which models were affected. A Dell spokeswoman said the software began getting installed on laptops in August. Dell added PCs shipping would not contain the bug in the future.

Advertisement

The company added it would provide customers with instructions to permanently remove the certificate by email and on its support website.

Advertisement

In the meanwhile, you can visit this website to check if your Dell computer is vulnerable. (Update: the company has issued instructions to remove the fraudulent certificate.)

The discovery comes nearly six months after Lenovo was caught pre-installing its own, self-signed root certificates on its machines. The certificates were provided by an adware advertising company called Superfish. Lenovo has since been caught in another such practice, where it was found to force installing suspicious programs on startup.

Advertisement

As for Dell, the digital certificate in question comes preinstalled as a root certificate and contains its private key. An attacker can exploit the vulnerability and use the key to sign certificates for other non-HTTPs websites. This could allow an attacker to decrypt encrypted Web browser traffic without a victim noticing anything. The vulnerability could allow an attacker to get fake Web pages pretend to be any other site, as Web browsers installed on a victim's Dell machine will trust any certificate issued by eDellRoot. For instance, a fake webpage can tap on eDellRoot-signed SSL certificate to pretend it's your banking website.

(Also see: Lenovo Covertly Downloading, Installing Software on Its Windows PCs: Reports)

"Dell seems to be repeating the Lenovo Superfish fiasco. With the pre-installed certificate and its private key, any website can claim to be any other site and Dell computers wouldn't be able to tell the difference," Mikko Hypponen, Chief Research Officer at F-Secure told Gadgets 360 in a statement. "Bad stuff," he added.

Advertisement

As researchers point out, an attacker could get access to a victim's username, passwords, session cookies, and other sensitive information. The certificate can also be used to sign malicious apps and the computer wouldn't be able to tell a difference. Users are also reporting that it seems impossible to get rid of the digital certificate as even if you delete it, it pops-up right back after a reboot.

"'You have a private key that corresponds to this certificate'," wrote Joe Nord, a security researcher. "This is getting very fishy! As a user computer, I should NEVER have a private key that corresponds to a root CA. Only the certificate issuing computer should have a private key and that computer should be ... very well protected!"

Nord confirmed that his computer was vulnerable to attacks after visiting an HTTPS test website, which if visited from a Web browser on an unaffected computer will flag vulnerabilities in the webpage. Nord noted that Google's Chrome, Microsoft's Edge and Internet Explorer showed no warnings. Mozilla Firefox, however, alerted trust issues with the certificate on the said website.

Written with inputs from AFP

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Cloudflare Is Down Again For the Second Time in Weeks: See Affected Sites
  2. ACT Fibernet Launches New Broadband Plans With Free OTT Subscriptions
  3. Flipkart Buy Buy 2025 Sale: Nothing Phone 3, Phone 3a Deals Revealed
  4. HMD 101, HMD 100 With Built-In Radio Launched in India at These Prices
  5. Motorola Edge 70 With Pantone's 2026 Colour, Swarovski Crystals Launched
  6. OnePlus 15R Surfaces on Benchmarking Site Ahead of India Launch
  7. Nothing Phone 3a Lite Goes on Sale in India at This Price
  8. Vivo S50 Colour Options, Key Features Surface Online Ahead of Launch
  9. OTT Releases of the Week (Dec 1 – Dec 7): Know What to Watch
  10. Realme 16 Pro+ 5G New Leak Reveals Storage and Colour Variants
  1. Motorola Edge 70 India Launch Teased; Flipkart Availability Confirmed: Expected Specifications, Features
  2. Google’s Year in Search 2025: Top Trending Topics in India—From Gemini to Squid Games
  3. Vivo S50 Colour Options, Key Features Surface Online; Could Launch in India as Vivo V70
  4. CFTC Clears Path for Spot Crypto Trading on Regulated Platforms for the First Time
  5. Realme 16 Pro+ 5G Colour Options, Memory Configurations Leaked Again; Tipped to Launch With 7,000mAh Battery
  6. Cloudflare Outage Blocks Access to Several Websites Including BookMyShow, SpaceX, Coinbase
  7. Samsung Galaxy S26 Series to Offer Built-In Support for Company's 25W Magnetic Qi2 Charger: Report
  8. Airtel Discontinues Two Prepaid Recharge Packs in India With Data Benefits, Free Airtel Xtreme Play Subscription
  9. Samsung Galaxy Phones, Devices Are Now Available via Instamart With 10-Minute Instant Delivery
  10. NotebookLM App Gets an In-Built Camera, Lets Users Upload Images as a Source
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.