Dell: When going cheap means going insecure

kblessinggr

PedoBeard
Sep 15, 2008
5,723
80
0
G.R., Michigan
www.kbeezie.com
Dell ships motherboard with malicious code | ZDNet

Dell ships motherboard with malicious code

Dell has confirmed that some of its PowerEdge server motherboards were shipped to customers with malware code on the embedded server management firmware.

The infected motherboard was found on replacement Dell PowerEdge R410 rack servers, according to a post on a Dell support forum.

A Dell representative confirmed the issue after a customer received a call warning about the infected motherboard.

As part of Dell’s quality process, we have identified a potential issue with our service mother board stock, like the one you received for your PowerEdge R410, and are taking preventative action with our customers accordingly. The potential issue involves a small number of PowerEdge server motherboards sent out through service dispatches that may contain malware. This malware code has been detected on the embedded server management firmware as you indicated.

We take matters of information security very seriously and believe that any impact to a customer’s information security is unlikely. To date we have received no customer reports related to data security. Systems running non-Windows operating systems are not vulnerable to this malware and this issue is not present on motherboards shipped new with PowerEdge systems.


The company did not provide any additional details.

UPDATE: After the publication of this story, Dell emailed the following statement from Forrest Norrod, vice president and general manager of server platforms.:

Dell is aware of the issue and is contacting affected customers. The issue affects a limited number of replacement motherboards in four servers - PowerEdge R310, PowerEdge R410, PowerEdge R510 and PowerEdge T410 – and only potentially manifests itself when a customer has a specific configuration and is not running current anti-virus software. This issue does not affect systems as shipped from our factory and is limited to replacement parts only. Dell has removed all impacted motherboards from its service supply chain and new shipping replacement stock does not contain the malware. Customers can find more information on Dell’s community forum.

Right up there back when Apple had ipods with viruses on them new out of the box, some emachines from walmart had spyware/malware on them before, and least 10 other companies. The main correlation is that the affected parts were almost always manufactured or packaged in Asia or South America.

I'm just curious how much money is loss as a result of extra quality assurance to keep their own cheap outsourced supply chains clean.

[PS: If I ever buy a pre-built machine, I always nuke the harddrive with a clean install, though not quite sure how someone would do that with malware embedded on the firmware]
 


Just build your own - it's easy, cheaper, and no crap you don't want.

Plus you get a much better machine in regards to a stable power supply, good HD, etc...

Almost ALL the crap sold in ALL the box stores don't have adequate power supplies, and have the cheapest HD's, memory, etc... they can get away with.
 
PowerEdges aren't exactly cheap servers.

EDIT:

cheap as in cost not quality.
 
Just build your own - it's easy, cheaper, and no crap you don't want.

Plus you get a much better machine in regards to a stable power supply, good HD, etc...

Almost ALL the crap sold in ALL the box stores don't have adequate power supplies, and have the cheapest HD's, memory, etc... they can get away with.

Not cheaper or easier, but better, yes.