Dell does a Superfish, ships PCs with easily cloneable root certificates
Root certificate debacle that hit Lenovo now visits the House of Dell. — In a move eerily similar to the Superfish debacle that visited Lenovo in February, Dell is shipping computers that come preinstalled …
Context & Ripple Effects
Nine months after Lenovo shipped notebooks with the HTTPS-breaking Superfish adware, the same class of flaw has surfaced at Dell: PCs are leaving the factory with a private root certificate — eDellRoot — whose key is easily cloned, letting attackers forge trusted HTTPS sites in Chrome and Internet Explorer.
The playbook from February is repeating fast. When Superfish hit, Homeland Security publicly urged Lenovo customers to remove it; this time Dell moved within hours of disclosure, posting manual removal instructions and promising an automatic cleanup tool the same day.
First-order effects
- Dell customers face immediate SSL spoofing risk on any network attacker's hotspot until they run the manual fix or today's automatic update lands on their machine.
- Dell's brand takes the direct hit Lenovo absorbed in February — and unlike Lenovo, it cannot blame a third-party adware vendor, since eDellRoot is its own certificate.
Second-order effects
- Enterprise IT departments that standardized on Dell hardware must audit fleets for the certificate, shifting support costs onto corporate buyers just as they did with Lenovo's Superfish cleanup.
- The discovery invites scrutiny of what other OEMs preload into Windows certificate stores — echoing how the Superfish hunt spread to a dozen more apps carrying the same SSL-busting code.
Third-order effects
- If OEMs keep shipping convenience software built on shared root keys, regulators and security agencies may treat preinstalled certificate abuse as a systemic supply-chain problem rather than a per-vendor embarrassment — a precedent already set when DHS publicly waded into the Superfish affair.
The trend: PC makers' habit of preinstalling root-certificate-based software is collapsing under public security scrutiny, forcing rapid recalls of trust store changes across the industry.