📜 ⬆️ ⬇️

Dell is out of work again: you can easily find out its unique id through the company's proprietary software.

image

On Dell's laptops, they found another vulnerability , in addition to the recent history of incorrectly installed certificate. Now it turns out that the proprietary software Dell Foundation Services, used to support users, easily and without unnecessary questions gives everyone a unique computer identification number. Typically, this id is used by Dell support staff to assist users.

As usual, the trouble does not come alone - it is possible that the Dell proprietary software will find more than one vulnerability, since the focus has shifted to their laptops. By the way, it was the Dell Foundation Services that used the ill-fated certificate.

It has now become known that a leak of a unique id can occur even after the removal of this certificate - so the officially released utility for its removal in this case will not save. So far the only way out is to remove the specified software from the computer.
')
As a result, even if a user of a Dell laptop tries to encrypt, turn on Tor, anonymous browsing, or at least delete all cookies, the unique id of his computer will still be available for websites. One security expert made a verification site that retrieves this id from anyone who has logged on to it using a Dell computer.

A potential intruder, armed with id, can find out the warranty information of the compromised computer, and use the information obtained, for example, for greater persuasiveness in phishing.

Source: https://habr.com/ru/post/356926/


All Articles