5 ms·
A review of Huawei devices by the company I work for, Finite State, found numerous (and some trivial) backdoors in 55% of Huawei projects. It is briefly mentio
by rotten 7y ago
A review of Huawei devices by the company I work for, Finite State, found numerous (and some trivial) backdoors in 55% of Huawei projects. It is briefly mentioned in the article above. Here is more information on that report: https://finitestate.io/2019/06/26/report-finds-cybersecurity-vulnerabilities-embedded-within-huawei-devices/ https://finitestate.io/2019/06/26/report-finds-cybersecurity...
And here is a video of our CEO talking more about it:
https://finitestate.io/2019/10/03/security-weekly-podcast https://finitestate.io/2019/10/03/security-weekly-podcast
- Someone1234 7y agoWow that's a grossly misleading executive summary. Your company should be ashamed of itself. I read the report itself: - Devices came with a default username/password. Called a "backdoor." - Devices used password auth instead of public key cryptography for SSH out of the box. Called a "backdoor." - Default public key cryptography keys for SSH auth instead of password. Called a "backdoor." - Devices contained public certificate authorities. Called a "man in them middle." - Devices contained well known vulnerabilities in common open source software. If I had paid Finite State for this report, I'd fire them on the spot and blacklist them. I particularly love the Schrödinger's cat of public key SSH auth. If the vendor doesn't enable it by default it is a "backdoor" and if they do it is "hard-coded certificates" and thus a "backdoor." According to Finite State's logic I've never used a vendor that didn't contain multiple "backdoors." Particularly as doing so is impossible (since you need to enable public certificate SSH auth AND not provide users any way of actually using it). The thing that surprises me is that they found "backdoors" in only 55% of devices? Shouldn't it be 100%, or did you feel like misleading that much was too unbelievable (and people might e.g. read the report and call you out)? PS - No conflicts or stakes here (don't even run Huawei's stuff that I know of). Just decided to read the report because of the extraordinary claims made, found out there was nothing there.
- whatshisface 7y ago>If I had paid Finite State for this report, I'd fire them on the spot and blacklist them. Whoever paid Finite State for that report presumably was happy with the outcome that was arranged for them. Alternatively, they could have written the report on their own in order to drum up business and "reputation" in the cybersecurity industry.
- HorstG 7y ago"Built by a team with backgrounds in the U.S. Intelligence Community, Finite State provides ..." aka. a propaganda outlet of the US deep state and not even shy to mention it...
- Buge 7y agoIf something has a default password, default private key, or trusts a default public key, and that isn't clearly documented, that seems like a backdoor to me. It would be an undocumented way of Huawei or random hackers taking over your device. And even if it's documented, although it's not a backdoor, it's still generally bad for security. Any device with non-unique default passwords or default keypairs will generally have hackers scanning the internet to compromise them. The keypair should be randomly generated on first use. The device should prompt for what password to use on first use.
- im3w1l 7y agoThese are interesting points. It's clear that Huawei is being held to a higher standard than anyone else, but at the same time, the critique is fair. Wouldn't surprise me if this newfound paranoia leads to a golden age for cybersecurity, and a wave of new best practices.
- OnlineGladiator 7y ago> Wouldn't surprise me if this newfound paranoia leads to a golden age for cybersecurity, and a wave of new best practices. I'd be shocked if this happened. This requires politicians to both care about and understand cybersecurity enough to enforce it, and for there to be no opportunists looking to cash in on the ignorance of policy makers. People demanded more security after 9/11. We got the Patriot Act and the TSA, so the government spies on its own people and an agency that has proven 95% (!!!) of the time to fail to detect a weapon. https://onemileatatime.com/tsa-fails-tests-95-percent/ https://onemileatatime.com/tsa-fails-tests-95-percent/ Ronald Reagon declared a war on drugs - I've already made this comment too political so I won't delve into that. For anything complicated enough the general public cannot easily understand it, there is no incentive for politicians to actually care about it. They can just give it lip service with a few talking points and then never actually do anything actionable.
- tptacek 7y agoThis report is pretty weak. I'm not sure I can nail down the "55%" number, but it's counting things like out-of-date OpenSSL, accounts in /etc/shadow, and at one point a survey across whole firmware images counting "memcpy" and "execl".
- ryanlol 7y ago>by the company I work for, Finite State Do you get paid for misleading people?
- ryacko 7y agoMaybe you guys should talk to Congress about it, there might be the political will to prevent the import of badly written code.
- rotten 7y agoMy understanding is that we have been.