Dell Confirms Loophole on Its PCs Can Let Hackers Snoop on You

Advertisement
By Manish Singh | Updated: 24 November 2015 14:45 IST

Leading PC manufacturer Dell is being accused of shipping its desktops and laptops with a self-signed digital certificate dubbed eDellRoot that could be exploited by hackers to leave the system vulnerable to man-in-the-middle attacks, letting them snoop on Internet traffic. Several users have confirmed on forums and social media networks that their Dell computers has the eDellRoot certificate preinstalled. The US-based company has acknowledged a security vulnerability in the said certificate.

"The recent situation raised is related to an on-the-box support certificate intended to provide a better, faster and easier customer support experience," Dell said in a statement to Reuters. "Unfortunately, the certificate introduced an unintended security vulnerability."

Advertisement

Dell declined to say how many PCs or which models were affected. A Dell spokeswoman said the software began getting installed on laptops in August. Dell added PCs shipping would not contain the bug in the future.

The company added it would provide customers with instructions to permanently remove the certificate by email and on its support website.

Advertisement

In the meanwhile, you can visit this website to check if your Dell computer is vulnerable. (Update: the company has issued instructions to remove the fraudulent certificate.)

The discovery comes nearly six months after Lenovo was caught pre-installing its own, self-signed root certificates on its machines. The certificates were provided by an adware advertising company called Superfish. Lenovo has since been caught in another such practice, where it was found to force installing suspicious programs on startup.

Advertisement

As for Dell, the digital certificate in question comes preinstalled as a root certificate and contains its private key. An attacker can exploit the vulnerability and use the key to sign certificates for other non-HTTPs websites. This could allow an attacker to decrypt encrypted Web browser traffic without a victim noticing anything. The vulnerability could allow an attacker to get fake Web pages pretend to be any other site, as Web browsers installed on a victim's Dell machine will trust any certificate issued by eDellRoot. For instance, a fake webpage can tap on eDellRoot-signed SSL certificate to pretend it's your banking website.

(Also see: Lenovo Covertly Downloading, Installing Software on Its Windows PCs: Reports)

"Dell seems to be repeating the Lenovo Superfish fiasco. With the pre-installed certificate and its private key, any website can claim to be any other site and Dell computers wouldn't be able to tell the difference," Mikko Hypponen, Chief Research Officer at F-Secure told Gadgets 360 in a statement. "Bad stuff," he added.

Advertisement

As researchers point out, an attacker could get access to a victim's username, passwords, session cookies, and other sensitive information. The certificate can also be used to sign malicious apps and the computer wouldn't be able to tell a difference. Users are also reporting that it seems impossible to get rid of the digital certificate as even if you delete it, it pops-up right back after a reboot.

"'You have a private key that corresponds to this certificate'," wrote Joe Nord, a security researcher. "This is getting very fishy! As a user computer, I should NEVER have a private key that corresponds to a root CA. Only the certificate issuing computer should have a private key and that computer should be ... very well protected!"

Nord confirmed that his computer was vulnerable to attacks after visiting an HTTPS test website, which if visited from a Web browser on an unaffected computer will flag vulnerabilities in the webpage. Nord noted that Google's Chrome, Microsoft's Edge and Internet Explorer showed no warnings. Mozilla Firefox, however, alerted trust issues with the certificate on the said website.

Written with inputs from AFP

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Nothing Ear 3a, CMF Buds Neo Visit Regulatory Databases, Might Launch Soon
  2. Hisense Launches U7SE 144Hz ULED Mini-LED TV Series in India
  3. Sony Bravia 7II 4K TVs With Cognitive Processor XR Debut in India
  4. Apple's First Foldable iPhone May Get White Colourway, VC Cooling
  5. Asus Unveils Zenbook 14 at Computex 2026, New Vivobook S Series Tags Along
  6. iPhone 17 Won't Start After Battery Runs Out? Apple Says iOS 26.5.1 Fixes It
  7. Samsung Galaxy Fit 4 Could Debut Alongside Galaxy S26 FE
  1. Nothing Ear 3a, CMF Buds Neo Spotted on Regulatory Databases Ahead of Anticipated Debut
  2. Samsung Galaxy Z Fold 8, Galaxy Z Fold 8 Ultra Could Feature Vastly Different Designs, Leaked Dummy Units Suggest
  3. Hisense U7SE 144Hz ULED Mini-LED TV Series With Up to 100-Inch Screens Launched in India: Price, Features
  4. Vivo Y500 Surfaces on Bluetooth SIG Database With Multiple Model Numbers, Could Launch Soon
  5. Asus Ascent QN10 Mini PC With Snapdragon X2 Elite Chipset Showcased at Computex 2026
  6. MSI Showcases New Katana, Venture Laptops and Crosshair A16 HX MLG Edition at Computex 2026
  7. Acer TravelMate P6 14 AI and P2 Spin 14 Unveiled, Acer TravelMate X2 15 and X2 14 Tag Along
  8. Sony Bravia 7II 4K TVs Launched in India With Cognitive Processor XR, Dolby Vision: Price, Features
  9. Asus TUF 16 (2026) Gaming Laptop Unveiled Alongside ExpertBook B5 Flip G2 (2026) at Computex 2026
  10. Asus Zenbook 14, Vivobook S14, Vivobook S16, Vivobook S14 Flip and Vivobook S16 Flip Launched at Computex 2026
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.