A thread on Reddit appeared earlier today (Nov. 23) detailing Reddit user Rotorcowboy's discovery of a Dell certificate, called eDellRoot, upon a recently made XPS 15 laptop. Rotorcowboy discovered that the certificate contained a private key, and was able to extract it using commonplace hacker tools. On a recently made Dell XPS 13, we found a second self-signed certificate, called DSDTestProvider, that also contained a private key -- a big security mistake.
Anyone with a recent Dell laptop can test for the presence of the eDellRoot certificate by visiting https://bogus.lessonslearned.org/, which uses that private key to authenticate itself as Dell. If you see an image of a ninja dog, you might be in trouble.