Dell Reportedly Shipping Another Dangerous Root Certificate on Its PCs

Advertisement
By Manish Singh | Updated: 25 November 2015 17:27 IST

Another root certificate vulnerability has been found on at least some Dell's Windows-powered computers. Earlier this week, the US-based computer juggernaut was caught shipping some of its recent PCs with a self-signed eDellRoot digital certificate which put its customers' privacy and security at risk.

It turns out, eDellRoot wasn't the only self-signed digital certificate that could allow attackers to impersonate websites and steal a user's information. Another root certificate called DSDTestProvider has been found by researchers on some Dell systems that could potentially be abused by attackers to perform the same man-in-the-middle attacks the eDellRoot certificate allowed, allowing attackers to snoop on user data and spoof encrypted pages.

"Dell System Detect installs the DSDTestProvider certificate into the Trusted Root Certificate Store on Microsoft Windows systems. The certificate includes the private key," wrote researchers at Carnegie Mellon University.

Advertisement

"This allows attackers to create trusted certificates and perform impersonation, man-in-the-middle (MiTM), and passive decryption attacks, resulting in the exposure of sensitive information."

Advertisement

Dell System Detect (DSD) is designed to interact with the Dell Support website. The researchers note that Dell systems that have been re-imaged, a popular process in which users remove all the applications that come pre-installed on the system and re-install them, are not affected. Some Dell systems don't come with the said certificate at all - those computers are not affected either. As of now, exactly which PCs ship with the DSDTestProvider certificate is not known.

The certificate is identical to the eDellRoot, which means that an attacker could generate certificates by the DSDTestProvider CA too, and impersonate websites and other services, emails, and decrypt network traffic among other things.

Advertisement

On Monday, Dell acknowledged that its eDellRoot certificate is riddled with an "unintended security vulnerability." The company also published an 11-page document with instructions on how to get rid of the said certificate. Dell is yet to acknowledge any vulnerability in the DSDTestProvider certificate.

 

For details of the latest launches and news from Samsung, Xiaomi, Realme, OnePlus, Oppo and other companies at the Mobile World Congress in Barcelona, visit our MWC 2025 hub.

Advertisement
Popular Mobile Brands
  1. iPad Air (2026) With M4 Chip Launched in India at This Price
  2. iQOO Z11x 5G Will Launch in India on This Date
  3. OnePlus 15T Details Revealed; New Telephoto Lens, Bigger Battery Confirmed
  4. Here's When the Oppo Find X9 Ultra Will Be Launched Globally
  5. Here's When the Oppo K14 5G Will Launch in India: See Expected Specs
  6. Samsung 'Holi Hai' Sale Brings Offers on Bespoke AI Appliances
  7. iPhone 17e Launched in India With MagSafe, 48-Megapixel Camera: See Price
  8. iQOO 15R Goes on Sale in India Today: Know Price and Offers
  9. Xiaomi 18 Series Leak Suggests Major Camera Upgrades Over Predecessor
  10. Nothing Phone 4a Will Go on Sale in Bengaluru at a Drop Event on This Date
  1. Samsung Announces ‘Holi Hai’ Sale With Cashback on Bespoke AI Appliances
  2. Kiss of the Spider Woman OTT Release Date: Know When and Where to Watch it Online
  3. Vanchana OTT Release: When and Where to Watch the Courtroom Drama
  4. Xiaomi 18, Xiaomi 18 Pro, Xiaomi 18 Pro Max Early Leak Reveals Rear Camera Details
  5. Meta AI Reportedly Testing Personalised Shopping Recommendations to Compete With ChatGPT, Gemini
  6. Oppo Find N6 Reportedly Appears at MWC 2026; Company Confirms March Launch in China
  7. Resident Evil Requiem Becomes Highest User Rated Game of All Time on Metacritic
  8. MWC 2026: Tecno Camon 50 Ultra 5G Unveiled With 6,500mAh Battery, 50–Megapixel Camera
  9. Vivo Y21 5G With Dimensity 6300 Chip Listed on Cellular Operator’s Website Ahead of Launch
  10. Tecno Pop X 5G Allegedly Listed on BIS, IMEI Websites; Could Launch in India Soon
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.