3 ms·
According to this post on Reddit, it is real and ZTE is planning on fixing it: http://www.reddit.com/r/Android/comments/tkc45/zte_backdoor/c4ney1w http://www.re
by Xuzz 14y ago
According to this post on Reddit, it is real and ZTE is planning on fixing it: http://www.reddit.com/r/Android/comments/tkc45/zte_backdoor/c4ney1w http://www.reddit.com/r/Android/comments/tkc45/zte_backdoor/...
- Zirro 14y agoBy fixing it, I assume they mean removing this backdoor and put in a new one? If they remove it altogether, there's not much reason to have it there in the first place.
- bri3d 14y agoDoes the reason for the backdoor really have to be to allow malicious remote access (hence requiring a replacement backdoor)? I highly doubt, considering the obvious nature and simplicity of the binary, that clandestine remote access (i.e. by the Chinese government or other such tinfoil hat theories) was the idea. Especially given the name of the binary, I suspect some ZTE engineer was tasked with writing a desktop or mobile sync application that they decided needed root access for some reason. Said engineer then made a major mistake and decided a non-unique plaintext secret stored in the binary was adequate security. This happens all the time - see the recent RuggedCom "backdoor" fiasco [0]. It's happened at places I've worked, too, and it's not exactly new in the industry as a whole. An engineer was uninformed or ignored security best practices and wrote code with a vulnerability. The vulnerability will be patched out. It's a big deal and it sucks (why were all setuid binaries not audited, at least to the level that basic oversights like this one would be noticed?), but at least in my mind it's not some kind of secret government control backdoor conspiracy - it's just a horrible bug. [0]: http://www.nerc.com/fileUploads/File/Events%20Analysis/A-2012-05-07-01_Ruggedcom_Unauthorized_Access_Vulnerability.pdf http://www.nerc.com/fileUploads/File/Events%20Analysis/A-201...
- tomp 14y agoI fail to comprehend how you can fix a backdoor.
- nbpoole 14y agoThe backdoor is a setuid-binary that gives a root shell when prompted with the correct "password." Deleting the binary removes the backdoor.
- rmserror 14y agoA discovered backdoor is a vulnerability. You fix the vulnerability.
- tomp 14y agoI understand that, but I meant it more in a philosophical way. The backdoor is not a bug (it's hard for me to imagine that the backdoor was included by accident), so you can't fix it. You can only remove it. Also, it's not a vulnerability either (from ZTE's point of view). It's a feature.
- majmun 14y agoYou make it more stealth.