TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Dell is posting unsigned updates to their website which fail to install

154 pointsby luu6 months ago

6 comments

panny6 months ago
&gt;Bad news: Dell is posting unsigned update executables to their website labeled “critical” which then fail to install due to the good news<p>If I were a hacker with no access to the signing keys, I&#x27;d probably label my updates as critical too, so you would try to find a way around the update signing.
评论 #42262154 未加载
评论 #42262548 未加载
评论 #42279488 未加载
评论 #42262143 未加载
klaas-6 months ago
yesterday they were also serving a update catalog index that did not match it&#x27;s signature <a href="https:&#x2F;&#x2F;downloads.dell.com&#x2F;catalog&#x2F;CatalogIndex.gz" rel="nofollow">https:&#x2F;&#x2F;downloads.dell.com&#x2F;catalog&#x2F;CatalogIndex.gz</a> &#x2F;&#x2F; <a href="https:&#x2F;&#x2F;downloads.dell.com&#x2F;catalog&#x2F;CatalogIndex.gz" rel="nofollow">https:&#x2F;&#x2F;downloads.dell.com&#x2F;catalog&#x2F;CatalogIndex.gz</a> -- but that was fixed after I complained<p>and their idrac based firmware updater downloads http(s):&#x2F;&#x2F;downloads.dell.com&#x2F;Catalog&#x2F;Catalog.xml.gz without checking the signature -- and by default without verifying https certificates when using https :D
SilasX6 months ago
Wow that’s almost as bad as Firefox five years ago … except this probably doesn’t compromise privacy addons that will get someone killed.<p><a href="https:&#x2F;&#x2F;hacks.mozilla.org&#x2F;2019&#x2F;05&#x2F;technical-details-on-the-recent-firefox-add-on-outage&#x2F;" rel="nofollow">https:&#x2F;&#x2F;hacks.mozilla.org&#x2F;2019&#x2F;05&#x2F;technical-details-on-the-r...</a>
ganzuul6 months ago
Dell must have calculated that Microsoft will take the blame for this.
bananapub6 months ago
I mean, someone is, who knows if it is Dell or not. probably Dell doesn&#x27;t know either, based on their usual software quality.
likeabatterycar6 months ago
Or the upload to their CDN was truncated or corrupted, and the signature check worked as designed.<p>But let&#x27;s not let an opportunity to paint Dell as some evil yet incompetent corporation slip through our fingers.
评论 #42262248 未加载
评论 #42262117 未加载