5 ms·
Backdoor account discovered in more than 100k Zyxel firewalls, VPN gateways
- based2 6y agohttps://www.reddit.com/r/sysadmin/comments/kotu67/zyxel_backdoor_found/ https://www.reddit.com/r/sysadmin/comments/kotu67/zyxel_back... https://en.wikipedia.org/wiki/Zyxel https://en.wikipedia.org/wiki/Zyxel
- chrisbolt 6y agohttps://news.ycombinator.com/item?id=25539876 https://news.ycombinator.com/item?id=25539876
- anakaine 6y agoThis and a little looking on Shodan makes for a scary tale of negligence at scale.
- RhodesianHunter 6y agoYou just described the entire industry
- sloshnmosh 6y agoThis reminds me of the guy that discovered a backdoor in his router after he forgot the admin password over the Christmas holidays. https://github.com/elvanderb/TCP-32764 https://github.com/elvanderb/TCP-32764 There is helpful hints in that research that enabled me to view the firmware of my own router
- wallacoloo 6y ago> Patches are currently available only for the ATP, USG, USG Flex, and VPN series. Patches for the NXC series are expected in April 2021, according to a Zyxel security advisory. 4 months to deliver a security patch of this significance? Would love to know what kind of situation leads to that kind of latency.
- usrnm 6y agoThey had to figure out what backdoor to replace it with
- tapper 6y agoThis is why I use OpenWrt in my network!
- vmception 6y agoIts okay, they all had nothing to hide
- cbozeman 6y agoIts almost as if Chinese companies are either just arms of the state, or thoroughly infiltrated by state actors! I don't think US-based hardware manufacturers are really any better though. To me this just illustrates the need for fully open-sourced hardware and software with domestic production facilities.
- manuelabeledo 6y agoZyxel is Taiwanese. Also, this is more likely a case of incompetence, not maliciousness.
- coolgod 6y agoHow do you know Taiwan doesn't have malicious state actors behind these backdoors? Is it because they aren't in a China ruled by the evil CCP?
- cutemonster 6y agoOr could it be an insider job? Some execs or managers demanding a backdoor, then secretly privately selling the secret password to various nation states and private security companies (for personal profit)
- coolgod 6y agoThis is a valid possibility, interesting to see such double standards applied to different tech companies based on the residence of their HQ.
- manuelabeledo 6y agoWhy would they? Also, why expose it in such an obvious way?
- Bancakes 6y agoIncompetence is a form of malice in cases like this.