5 ms·
HP admits to backdoors in storage products
- RexRollman 13y agoI just don't understand why companies are still pulling this crap. It puts their customers at risk.
- bigiain 13y agoBecause their customers are the pointy-haired-bosses who're asking "Why the hell to we need to wait for them to send a service tech out? Why can't they fix this online?" when shit is actually going down - rather than the network/storage/security guys who point out the risks of things that haven't happened yet.
- drdaeman 13y agoYea, but techies should at least use PKI with HSM guarding the private key, not 7-char almost-dictionary-based password.
- DavidBradbury 13y agoBut it has numbers replacing the letters! That makes it hard for computers to guess!!!
- drdaeman 13y agoOh, right. Sounds like the pointy-haired boss decided upon the password himself.
- CrLf 13y agoWell, so I won't tell you about the vendors that give you the stare if you change the root password on their devices from the factory default. Like, "You changed the sysadmin password? Why?" ~sigh~
- deleted 13y ago[deleted]
- blinkingled 13y agoMisleading article title. (What better to expect from The Register?) HP admitted there's a vulnerabiity that with customer provided access and permission can allow HP support to access underlying os of the storage device. At most a reboot is possible not data access. So this is just another stupid vulnerability that'll be fixed soon - not a backdoor.
- nness 13y agoI would say otherwise, seeing as that it was a known vulnerability, and left in intentionally. Very much a backdoor.
- ikurei 13y agoWhy "intentionally". May be it was put there intentionally but leaving it that way was a mistake. I don't think that's a backdoor, just from the article.
- venomsnake 13y agoI would say that both malice and stupidity of HP are well balanced in this case.
- ikurei 13y agoWhy "intentionally". May be it was put there intentionally but leaving it that way was a mistake. I don't think that's a backdoor, just from the article.
- ikurei 13y agoIt doesn't say it was left there intentionally. We don't have (or this article does not give) information enough to call it a backdoor.
- yen223 13y agoAccidentally leaving an open administrator account is a bug as old as time. I won't necessarily attribute it to malice. That said, it's still a backdoor, whether it was left there intentionally or not. I'd have a hard time trusting HP products after this.
- exgeocitiesuser 13y agothis keeps getting better and better
- Fuxy 13y agoHP nicely covering their ass to not get associated with the NSA scandal happening at the moment. I don't know if the fact that they are trying so hard is an indication that they actually are but this is suspicious.
- sgloutnikov 13y agoLooks more like name/brand smearing to me (from the competition?). Especially convenient in the midst of the NSA scandal.
- mtgx 13y agoIt's not smearing when it's true. Just plain old exposing.
- kryten 13y ago1. SSH to the box 2. Username: hpsupport 3. Password (from SHA1 lookup): badg3r5 Yes that shit. We have some of this kit in and I've tested it and it works absolutely spot on. Fortunately it's all firewalled off but it's not the sort of crap you want on your doorstep. Nothing to do with the NSA this - just a crappy decision somewhere which is designed to make HP support's life easier. As someone else said: this bug is as old as time.
- iuguy 13y agoCan you do me a massive favour and paste the output of the following commands? uname -a cat /proc/cpuinfo cat /proc/meminfo cat /etc/passwd If I can get a firmware image I'll take a look early next week and do an analysis follow-up.
- wslh 13y agoWelcome to the 80s. Seems like software development is moving in circles
- coldcode 13y agoSadly our parent company uses HP to handle all security and computer support/installation. Around here they are known as Helpless People.