3 ms·
backdoor means a secondary access point that defeats the security features of the primary. In the door analogy, the home owner spends a ton on a lock and camera
by blank429384jf 2mo ago
backdoor means a secondary access point that defeats the security features of the primary. In the door analogy, the home owner spends a ton on a lock and camera for the front door but doesn't even have a deadbolt on the back.
- close04 2mo agoEvery definition of a “backdoor” in computing implicitly or explicitly considers it hidden/covert. In the house analogy you don’t see the backdoor when approaching the front. If it was just “an alternative everyone knows about and can be broken easier than the front door” then it probably would have been called “a window”. Most login forms have a weaker option like a SMS 2FA or password reset fallback. Nobody calls it a backdoor. It’s just a crappy second front door, or window.
- blank429384jf 2mo agoI'm probably mistaken, but I've always referred to password resets as backdoors. Is there another term they could be classfied as?
- close04 2mo ago> Is there another term they could be classfied as? As an advertised feature of the product. Your personal definition doesn’t match the general understanding of the word and concept. By your definition every window on a house or car is a “backdoor”. Anything with an advertised fallback is a backdoor. And sometimes the “front door” is the back door: getting money from an ATM is less secure than with an ID at the bank teller.
- blank429384jf 2mo agoPassword resets aren't "backdoors" unless they contain a flaw the defeats any security protections. It's not just that the backdoor is less secure than the front, the backdoor has no security or is so easily defeated the security may as well not exist. I'm surprised the hidden aspect of backdoor is so forward in folks minds. In my thinking nothing in cyber security is hidden, I drop the obviously present hidden part of backdoor definition when it's used in yhe cyber security context.
- close04 2mo agoNo offense but I don’t think you have a clear enough definition in your head and you’re making it up as we go along and you get challenged. >> I'm probably mistaken, but I've always referred to password resets as backdoors > Password resets aren't "backdoors" unless they contain a flaw the defeats any security protections. You really have to make up your mind. It was “always” but then it wasn’t, and even as you put it you’d have been wrong almost every time to call a reset “a backdoor”. > I'm surprised the hidden aspect of backdoor is so forward in folks minds. Only because you misunderstand the meaning of the term, as made very clear above. Go through the wiki page for a “backdoor”. > In my thinking nothing in cyber security is hidden I wonder what all those security researchers do all day, with everything being so out in the open and known by everyone. > I drop the obviously present hidden part of backdoor definition when it's used in yhe cyber security context. You can drop it but then you’re just using the wrong definition and wrong understanding.
- blank429384jf 2mo agono offense taken. i shouldnt have included password resets in my def. it muddied the conversation. covert is part of a def, at least sometimes, but i think its still acurate to drop it. consider a machine with two copies of ssh running, one of 22 with authentication and another on 2222 with an automatic root login. the instance on 2222 would be considered a backdoor, even though its barely hidden. Swap the ports and it's an unauthenticated frontdoor, but i'd still call it a backdoor and expect everyone to know what i mean. the important part is its bypassing securit, not that its hidden.
- JacobKfromIRC 2mo agoThe Free Software Foundation (FSF) calls the update system used in Windows 10 a "back door" [1], I think because it installs updates automatically. This sounds like nonsense to me, because it implies that I installed a back door on my own machine by enabling automatic upgrades (on Trisquel). It's meaningful that the Windows 10 install method has no (official) way to disable it, but I don't think making something optional could make it not a back door, if it was one before. Even when automatic updates are disabled, I'm not going to be reading every update so the effect seems mostly the same, regardless of whether updates are automatic or not. The FSF's definition of "back door" (at the bottom of the linked page) is "any feature of a program that enables someone who is not supposed to be in control of the computer where it is installed to send it commands" which leaves a lot of ambiguity with the words "supposed to be". I am not sure how to interpret this definition. [1] https://www.gnu.org/proprietary/proprietary-back-doors.html#windows-update https://www.gnu.org/proprietary/proprietary-back-doors.html#...
- gmueckl 2mo agoThe FSF definition can be interpreted in absurd ways; a very uncharitable interpretation would classify any network stack connected to the internet as backdoor because random, potentially misdirected packages trigger code exécution on the target machine, even if only to figure out that the packet must be ignored.
- br0ceph 2mo agoI agree with any automatic updates being a back door. Doesnt really matter which platform, automatic updates are bad news. On windows it led to clownstrike. On BMW it led to dash ads. Theres infinite examples of auto updates being an attack vector for OEMs and other bad actors. Always disable updates on every product. Can always reenable as needed or even sideload updates.
- JacobKfromIRC 2mo agoHow do you decide when to update?
- purplemoonx 2mo agoI like where this is going. Can we refer to user data as “the garage”? And instead of hackers they should be “coons”. The headlines can read: ”Buncha Coons In The Garage Again” It’s more quaint