5 ms·
Relevant discussion a day ago: Vodafone Found Hidden Backdoors in Huawei Equipment https://news.ycombinator.com/item?id=19786102 https://news.ycombinator.com/
by expressrunning 7y ago
Relevant discussion a day ago:
Vodafone Found Hidden Backdoors in Huawei Equipment
https://news.ycombinator.com/item?id=19786102 https://news.ycombinator.com/item?id=19786102
- gnode 7y agoWhile this is being touted as a smoking gun, calling it a "backdoor" may be reaching: https://www.theregister.co.uk/2019/04/30/huawei_enterprise_router_backdoor_is_telnet/ https://www.theregister.co.uk/2019/04/30/huawei_enterprise_r...
- sp332 7y agoI think this article is disingenuous. It's telnet on a nonstandard port with hardcoded credentials, that was added back in after being removed when it was spotted in previous security testing. Edit: this according to one of the sources in the Bloomberg article, who claims to have read internal Vodaphone documents https://twitter.com/raistolo/status/1123283199348621312 https://twitter.com/raistolo/status/1123283199348621312
- strainer 7y agoA telnet service responds to a plain port scan. So it was categorically not hidden. Vodaphone explain this themselves in the linked register article: >It added the Telnet service was found during an audit, which means it can't have been that secret or hidden: "The issues were identified by independent security testing, initiated by Vodafone as part of our routine security measures, and fixed at the time by Huawei.
- DelightOne 7y agoSo a backdoor is okay incase it's not hidden?
- strainer 7y agoIf its not hidden, its not a threat to national security kind of "backdoor". A hidden backdoor will only respond to a secret token, you cant just knock on it and get asked "whats the hardcoded password?"
- gnode 7y agoA vulnerability is not as damning if it wasn't intentionally inserted to be a backdoor. It being easily discoverable suggests that there was no intention to hide it, and thus it was not intended to be a backdoor. If conversely the vulnerability was difficult to find externally, was publically unknown, and was seen being used for attacks, that would be suggestive of a deliberate backdoor, and far more damning.
- inflatableDodo 7y ago>I think this article is disingenuous. Is 'The Register'. Being disingenuous is their bread and butter when you tune out the comedic writing style. I used to follow their climate change reporting as an interesting counterpoint as they were biased towards trying to disprove it. These days they more or less ignore climate change as a topic compared to five or ten years ago, if you look at frequency of articles.
- gnode 7y agoI won't deny it's bad, but it's more of a smoking crater than a smoking gun. A genuine vulnerability existed, and it wasn't swiftly remove (apparently due to it being crucial to their manufacturing operations). Notwithstanding the potential for this to be an underhandedly engineered backdoor, there doesn't seem to be any evidence of it being more than an oversight similar to others common in the industry.
- codys 7y agoIn other words, they have plausible deniability because of how the backdoor was designed.
- ssnistfajen 7y agoHuawei's reputation has never been completely stellar, but I'm getting more and more skeptical of these "reports" and the motivation behind them. Rehashed old news fromm 2012 about a telnet port? Really? As always, rehashed old news is great for clicks when it's the correct boogeyman.