Ссылка
click to show
click to show
Are OEMs / Dell covering up incompetence or intentionally leaving security backdoors?
Summary
A white-hat (sp? whitehat) finds that OEM monitoring SW drivers, in this case Dell Technologies, have a huge security vulnerability surface. It seems it is being actively ignored and covered-up.
Quotes
Quote
Bugcrowd and Dell want me to delete this post. Absolutely not. WDTKernel.sys was mentioned in multiple articles this last decade, researchers never found the same vulnerabilities that I found nor did they bring evidence to the fact the same vulnerable code is being compiled to this day.
My thoughts
Can also see my original LTT post under Windows security here
Of course corporations don't want transparency of their ineptitude. But this seems intentional? Is this merely the car company covering up flaws because the fix is more expensive than a few deadly outcomes? (The Verdict movie reference) This case seems like intentionally covering-up a severe vulnerability multi-vector surface, possibly to maintain a insecurity backdoor into systems. It's on likely a billion of devices. Very infamously Lenovo was caught in the Superfish BIOS-level reinstall persistence scandal, and Sony BMG with the rootkit scandal.
Conspiracy theorists would say this is CIA NSA black ops maintaining backdoors on everyone. With Mythos supposedly finding hundreds if not thousands of vulnerabilities, is this intentional incompetence to help artificially create a case for "needing" AI by sabotaging the real human work? Or, "Never attribute to malice that which incompetence explains"?
Sources