7 ms·
not a backdoor?
by thatiscool 7y ago
not a backdoor?
- AdmiralAsshat 7y ago"Backdoor" usually implies the vulnerability was put in there intentionally.
- sarakayakomzin 7y agoyes, I believe that's why they used the word "Backdoor".
- dx87 7y agoThey might be alluding to the fact that depending on who manufactures the device, security vulnerabilities will be reported as a backdoor.
- AdmiralAsshat 7y agoAdmittedly I didn't read the whitepaper, but the CVEs that were mentioned on the page summary sounded like your run-of-the-mill stack overflow or string vulnerabilities. So yes, the end result might be the same (i.e. remote takeover), but I would hesitate to call them backdoors unless it was demonstrated that this vulnerability was intentionally known or left unfixed for the purposes of being abused by parties in the know.
- simion314 7y agoThe idea if the same bug was in a Chinese product the title would have been "backdoor injected" ... see yesterday and recent articles on HN.
- IAmEveryone 7y agoI searched and only found something about a vulnerability in "HiSilicone" hardware mentioned yesterday. That article mentions a pre-installed telnet server including accounts that can be started with the right command send over TCP. Whereas here, it's apparently a typical buffer overflow resulting in arbitrary (but BYOT (bring your own Telnet)) code execution. Sure, maybe Cisco is just better at disguising their backdoors for plausible deniability. But with what's known, intent seems far more likely in yesterday's case than this.
- trasz 7y agoA Telnet server is way too obvious for a backdoor. It’s more of a leftover debug feature.
- simion314 7y agoThe article title was different initially and was something that included backdoor,injected,Huawei(was no direct relation with Huawei). There were also many similar reports about US routes and IOT having default passwords or easy to guess passwords but each time the stupidity is assumed. Also the Windows "NSA key" article and comments were very convincing that for sure it was nothing evil and was never used anyway.
- TaylorAlexander 7y agoWell I suppose we don’t have enough information to determine whether it was put there intentionally or not. I recall from the Snowden leaks that the US has a well established program to maintain access to as many foreign networks as possible. A cozy arrangement with Cisco and/or a National Security Letter might help ensure such access is possible. https://www.aclu.org/other/national-security-letters https://www.aclu.org/other/national-security-letters
- __jal 7y agoThere has been more than one Cisco vulnerability that struck people as suspicious. I know it comes to my mind every time I see the string "Cisco zero day", whether or not it seems likely in any particular case.
- DyslexicAtheist 7y agoexcept with CISCO "backdoor" has 2 meanings: 1) CISCO's well documented efforts to intentinally put them into place in the canonical sense of the word (for LI): https://news.ycombinator.com/item?id=22251965 https://news.ycombinator.com/item?id=22251965 2) it is a well-known feature that is used to change the administrative distance of eBGP in order for an interior gateway routing protocol (IGP) to take precedence over an eBGP route. https://community.cisco.com/t5/networking-documents/what-is-the-bgp-backdoor-feature/ta-p/3154898 https://community.cisco.com/t5/networking-documents/what-is-...