3 ms·
> Dahua at first ignored ReFirm’s inquiries, then claimed the vulnerability was a simple error that had been fixed in the latest update. But when ReFirm looked
by ary 7y ago
> Dahua at first ignored ReFirm’s inquiries, then claimed the vulnerability was a simple error that had been fixed in the latest update. But when ReFirm looked through the updated firmware, they still found the same backdoor — just relocated in a different place in the code. (Huawei had done the same thing).
Regardless of which vendor we're talking about I fear that this simple admission of human error is going to repel any improvement justified by technological means. It is extremely easy, and entirely believable, to continuously blame human error, "junior devs", management, etc in the face of any discovered vulnerabilities.
The value of automated detection is to hopefully fuel a real boycott and/or government ban. I'm not specifically calling out Huawei here because I think it's entirely reasonable for other countries to do the same thing to U.S. companies. Hitting offenders in the only place it hurts, the bank account, is probably the only way inhibit this behavior.