3 ms·
Is this an actual backdoor, as in, put in there on purpose by the manufacturer? Sure sounds like it.
by beeboobaa3 2y ago
Is this an actual backdoor, as in, put in there on purpose by the manufacturer? Sure sounds like it.
- throwaway888abc 2y agomade by China-based Shanghai Fudan Microelectronics
- hangonhn 2y ago> After this second secret key was also cracked it was discovered that the key is common to all FM11RF08 cards, as well as other models from the same vendor (FM11RF32, FM1208-10), and even some old cards from NXP Semiconductors and Infineon Technologies. Even the ones not made by a Chinese company had the same backdoor. Perhaps, the original design had this backdoor and the manufacturers simply implemented the design. NXP is Dutch. Infineon is German.
- wkat4242 2y agoIt could be in the software layer too. Modern smartcards have 'applets' that can run custom code. The cards themselves trend to be quite generic. This can even be in high level languages like Java or basic. So if the code was there it's not the fault of the card manufacturer but the applet developer.
- JeffeFawkes 2y ago"Additional research revealed a hardware backdoor that allows authentication with an unknown key. Teuwen then used the new attack to obtain (“crack”) that secret key and found it to be common to all existing FM11RF08S cards." Static key, decrypts all cards of a given model regardless of user stored keys? Yep, it's a backdoor.
- kuroguro 2y agoBasically there's a master key that allows reading blocks that are supposed to be unreadable. > put in there on purpose by the manufacturer Hard to prove "on purpose" either way, my guess it was for debugging.
- deleted 2y ago[deleted]
- wkat4242 2y agoIf they put it there for debugging it certainly qualifies as "on purpose". No matter what the reasoning behind it was.
- kuroguro 2y agoTechnically. I'm saying there's a huge difference between what a layman might read "large org conspires to spy" and a possible dull reality of "some engineer neglects to remove convenience feature".
- hulitu 2y ago40 years ago, maybe. Today, no. (but hey, taking Croudstrike into account, everything is possible)