6 ms·
The title of this article is misleading. "Backdoor" implies a deliberate mechanism built into the software, but here there's no evidence that the vulnerability
by KerrickStaley 8y ago
The title of this article is misleading. "Backdoor" implies a deliberate mechanism built into the software, but here there's no evidence that the vulnerability wasn't simply a mistake.
- throwaway8879 8y agoIt's China. I'm not American and don't have a dog in this fight, but I'm inclined to believe that the Chinese are never up to any good.
- AYBABTME 8y agoThat's straight up racist.
- lawnchair_larry 8y agoIt has nothing to do with race. Stop throwing around that word.
- shawnz 8y agoI assume they meant the Chinese government, not the Chinese people.
- drusepth 8y agoIs that any less racist?
- TomMarius 8y agoIt's not racist at all, it's nationalist if anything.
- willhk 8y agoHow is being aware of and concerned about the activities of a government racist?
- Moodles 8y agoYes, it is a lot less racist actually. Are you serious?
- deleted 8y ago[deleted]
- mikestew 8y agoI say this without even the slightest hint of snark: are you sure you really know what that word means, and the dichotomy of race and government?
- EpicEng 8y ago...Yes, because the Chinese government is not a race? Obviously?
- diminoten 8y agoI think you're assuming some positive intent here that's definitely helpful to the conversation, but may not actually exist in this specific case. For our part, I think us sane people can all agree that it's the PLC that we are suspicious of, whereas the people of (and from) China are wonderful people.
- throwaway8879 8y agoI don't hate snakes. But I avoid them all the same so as not to get bitten. You seem to think I am making some sort of value judgement about the Chinese, I'm not. I don't trust anybody who isn't statistically trustworthy. That's all there is to it.
- Dirlewanger 8y agoYeah, those military divisions that they have that are constantly pinging virtually every IP address in the world looking for vulnerabilities...they surely have good in their heart!
- monocasa 8y agoI mean... All of the major governments do that, it's just IPs of botnets always tend to be Chinese or Russian since those tend to be the unpatched systems.
- dsfyu404ed 8y agoMaybe I'm not easily triggered enough but generally speaking when one says "the Chinese" or "the Nigerians' or "the Russians" in a discussion that's about international relations, geopolitics or similar, I tend to think they're talking about the nation and its government, not the people themselves.
- AYBABTME 8y agoIf that's the case, the distinction was subtle enough for me to miss, and probably a lot of others. It isn't hard to say "the Chinese government" if that's what parent meant. Instead saying "the Chinese" in response to an article about a Chinese company's product is clearly ambiguous. I don't see how it's okay to gratuitously say anything about "the Chinese" as if that was somehow a valid, well defined and understood group that warrants being judged and stereotyped in such a wide manner.
- bllguo 8y agoBut it blurs the distinction and it normalizes thinking about the Chinese people and the Chinese gov't in similar ways. Honestly I think it's irresponsible and naive - let's not pretend there isn't a rising undercurrent of anti-Chinese sentiment in the West.
- JamesBarney 8y agoAll the rising anti-Chinese sentiment I've seen seems mostly geopolitical and not ethnic.
- T800M101 8y agoThe fact that national governments aren't to be trusted is not racist. Your implication and terribly bad misapplication of the word "racist" is more disturbing than someone not trusting said foreign government.
- deleted 8y ago[deleted]
- ryanlol 8y agoWell, most of the Chinese people don't really seem to mind the fact that their government runs literal concentration camps. Perhaps it's fair to criticize them?
- monocasa 8y agoSo what, the Chinese aren't allowed to write bugs anymore?
- mar77i 8y agoWell usually, Microsoft is on the receiving end of the "vulnerability found" game. To me it would appear as if they're making sure that every single thing they discover requires media attention.
- z2 8y agoCould you please clarify if you mean all 1 billion Chinese nationals, their government, people anywhere of Chinese ethnic origin, or Chinese-domiciled companies and their workforce in general?
- bowmessage 8y agoWhich is exactly how you'd want your backdoor to be perceived when discovered.
- jtr_47 8y agoI believe any piece of hardware that is sold local or internationally has a backdoor of some kind for government access. There are no mistakes. No company will say this, due to "laws" or "NDA" from a government that prevents the company from discussing these "mistakes."
- ma2rten 8y agoDo you have any evidence for this claim?
- kekebo 8y agoIt's generally hard to come by, leaving lots of room for assumptions. There was evidence of NSA tampering with ordered hardware in transit in the Snowden files, next to indications / speculations around certain cisco routers and even more about Intels Management Engine. But despite the last two being probable candidates I can't recall hard evidence for them.
- lawnchair_larry 8y agoTargeted interdiction is a far cry from what the parent comment alleges. Targeting shipments to backdoor or bug an item quite obviously happens everywhere in the world and has since the dawn of time. The Snowden files said nothing about Intel’s ME. That isn’t a backdoor either. It’s a great place to put one, but there are lots of great places to put backdoors, and that doesn’t mean that’s what the manufacturer is doing.
- jtr_47 8y agoYes. The recent Huawei article above.
- lawnchair_larry 8y agoYou are not correct. That is a logistical nightmare and would be impossible to keep secret.
- 8y ago
- gruez 8y ago>but here there's no evidence that the vulnerability wasn't simply a mistake. So what, you want proof that the backdoor is deliberate? To do that, you'd either need some sort of internal directive from up top (good luck finding that), or the backdoor was comically bad (eg. if (signed by PLA) return true;).
- shawnz 8y ago> So what, you want evidence that the backdoor is delibrate? If the title of the article is "backdoor found", then yeah. I'm of the opinion that it was an intentional backdoor too, I think that was a pretty clear possibility to anyone who saw the initial writeup. But to come out and claim unambiguously that it was a backdoor is masquerading an opinion as news.
- monocasa 8y agoThis. A good example is Cisco's predilection to add "undocumented accounts" to it's routers. Those are definitely intentional backdoors. https://m.slashdot.org/story/343674 https://m.slashdot.org/story/343674
- __jal 8y agoYeah, I've always found it entertaining that their corporate culture is characterized by a unique multi-decade inability to stop those darn engineers from writing backdoor accounts. It would be more entertaining if I thought other vendors were less likely to be compromised[1]. [1] https://www.wired.com/2015/12/researchers-solve-the-juniper-mystery-and-they-say-its-partially-the-nsas-fault/ https://www.wired.com/2015/12/researchers-solve-the-juniper-...
- ryanlol 8y ago>you want proof that the backdoor is deliberate? Seems like a very reasonable request. The strictly local nature of this "backdoor" strongly suggests that it is not in fact a backdoor, if you're going to call it a backdoor maybe you should have the least bit of evidence to support that.
- burtonator 8y agoThis is the biggest problem with attribution in network security. If Huawei wanted to do this the smart way they would implement a backdoor that's VERY tough to find but could also be justified by stupidity. This way they have plausible deniability. "We're not malicious. We just screwed up!"
- ryanlol 8y agoWhy would anyone malicious bother hiding a LPE vulnerability in a driver like this? What's the point if you're going to need another backdoor to actually get code exec in order to exploit this backdoor?
- kosievdmerwe 8y agoBecause deniability is valuable in international relations? If a government can't prove something they aren't forced to act. If it was obvious the Chinese government did this, then other world governments would have to respond with sanctions and import bans.
- ryanlol 8y agoWhy would anyone want a LPE backdoor like this? You would need another backdoor to achieve RCE in an order to make use of your silly LPE backdoor.
- monocasa 8y agoI personally of the opinion that this is just a bug, and not an intentional bug That being said, there is value in a LPE as a part of a bigger exploit chain. There's all sorts of exploits that'll give you relatively unprivileged code execution, and you'd want to silently elevate in order to make yourself persistent for instance.
- ryanlol 8y agoWindows LPE bugs tend to be quite cheap and plentiful, I just can't see much value in inserting a bug like this to possibly make it slightly cheaper on a few specific machines.
- toddh 8y agoHow can you differentiate between a camouflaged back door and a mistake? It's clear you would want plausible deniability, so you would make it look like a mistake. And if you have mistake after mistake when do they stop being mistakes?
- deleted 8y ago[deleted]
- basch 8y agoThe conspiracy theorist in me would suspect that Huawei cloned or inherited existing backdoors from Cisco, Intel, Qualcomm code/tech they acquired. (not that they would necessarily be related to this news story.) If the US security sector blew the lid on the backdoors, they would also be exposing their own backdoors, thus all they can do is generate FUD towards Huawei, and hope that they never need to present evidence.