Live data from Hacker News

Vodafone Found Hidden Backdoors in Huawei Equipment

bloomberg.com

81–90 of 131 posts

Re: Vodafone Found Hidden Backdoors in Huawei Equipment

#81
post #74
post #17

Earlier quoted context omitted.

Intel ME _is_ a backdoor. The funny thing is that there are many more. Interesting how the EU is dealing with this - most media seems to focus on how badly china could be spying while the US proved they aren't trustworthy long before.

You haven't worked for large companies have you? Intel ME is NOT a backdoor. It may have vulnerabilities, sure. But none explicitly put in there. It was designed for a specific purpose- troubleshooting enterprise computers. And it does that job amazingly well. No more IT guy guiding me when he can just do all the clicks himself.

It doesn't matter if it's a deliberate backdoor or not. It's a door, and I want to be able to close that door if I'm not using it, and Intel won't let me. Reducing attack surface is a security best practice exactly because any software can have bugs.

An allegory: imagine if an OS ran an SSH server and there was no way to turn it off or to control the keys it accepts. Maybe it has no bugs (you can't see the source code). Maybe it has no malicious intent or backdoors. As a security conscious computer owner, I still view its existence as a negative. I would like to be able to provably turn it off or control the keys it accepts.

Re: Vodafone Found Hidden Backdoors in Huawei Equipment

#82
post #12
post #5

Hard to know from the article, and Bloomberg does not have a good track record, if the 'backdoor' was a vulnerability , an unwanted feature or an actual backdoor. I might imagine a Chinese headline with "US firm Intel backdoors every CPU", which may or may not be true depending on your feelings on Intel ME

> Europe’s biggest phone company identified hidden backdoors in the software that could have given Huawei unauthorized access to the carrier’s fixed-line network in Italy, a system that provides internet service to millions of homes and businesses I think it is enough to be called a "backdoor".

A backdoor is a deliberate remote-access vulnerability that the creator intended to use for illegitimate access.

The same code, but intentional, is a bug and vulnerability, but not a backdoor. Same security implications, but a big difference wrt. culpability, appropriate punishment, and expectations of future behavior.

Re: Vodafone Found Hidden Backdoors in Huawei Equipment

#83
post #64
post #45

I was skeptical about "boycotting" China and Huawei for a long time; just thought that they make cheap phones, and innovative tech, so why not. I changed 180 degrees when I started learning about the growing Chinese influence, how politically corrupt they are, and the excessive violence and human rights violations exercised against minorities. China is growing its economic dominance very quickly. They are gaining man…

I swapped out China for US, Huawei for Google/Apple/Amazon/Facebook, Asian for South American, and it all still made sense.

US is a democracy with an independent judiciary. China isn't.

Google, Apple etc are public companies. Huawei is state controlled.

So it only makes sense if you completely ignore the basic facts.

Re: Vodafone Found Hidden Backdoors in Huawei Equipment

#84
post #18

As Jon Gruber says: "Bloomberg, of course, is the publication that published “The Big Hack” in October — a sensational story alleging that data centers of Apple, Amazon, and dozens of other companies were compromised by China’s intelligence services." "The story presented no confirmable evidence at all, was vehemently denied by all companies involved, has not been confirmed by a single other publication (despite much…

Bloomberg publishes what thousands of articles a year. Some percentage of them are guaranteed to be wrong. That doesn't meant that the burden of truth should instantly shift towards them being untrustworthy based on a single article. Journalism depends on the public trusting them and in the current environment in which that trust is being eroded to have comments like this that dismiss Bloomberg entirely is reckless a…

     > That doesn't meant that the burden of truth should instantly shift towards them being untrustworthy based on a single article.
How many very high-profile articles need to be complete bullshit before it's time to start questioning the integrity of Bloomberg?

The Supermicro nothing-burger was supposedly the culmination of a year of effort by top-shelf journalists. They knew what they were doing, they had NOTHING to show for it and published anyway. I think that's irresponsible at best and more likely had ulterior motivations.

Re: Vodafone Found Hidden Backdoors in Huawei Equipment

#85
>Vodafone said in the report that Huawei would need to remove or inhibit a so-called telnet service—a protocol used to control devices remotely—that the carrier said was a backdoor giving Huawei access to sensitive data.

This seems like a diagnostic telnet port left open by accident. I'm very sceptical at this point at any American government or media finding a 'backdoor' in Huawei.

A backdoor implies this is intentionally left open to later get unauthorized access.

Why would anyone build a 'backdoor' on an open telnet port?

This seems intentionally blown out of proportion to fit a narrative.

Re: Vodafone Found Hidden Backdoors in Huawei Equipment

#86
post #74

Earlier quoted context omitted.

You haven't worked for large companies have you? Intel ME is NOT a backdoor. It may have vulnerabilities, sure. But none explicitly put in there. It was designed for a specific purpose- troubleshooting enterprise computers. And it does that job amazingly well. No more IT guy guiding me when he can just do all the clicks himself.

It doesn't matter if it's a deliberate backdoor or not. It's a door, and I want to be able to close that door if I'm not using it, and Intel won't let me. Reducing attack surface is a security best practice exactly because any software can have bugs. An allegory: imagine if an OS ran an SSH server and there was no way to turn it off or to control the keys it accepts. Maybe it has no bugs (you can't see the source cod…

Forcing upon users is wrong but calling it backdoor, as someone who sounds reasonably intelligent to other reasonably intelligent people is misleading and wrong too.

Re: Vodafone Found Hidden Backdoors in Huawei Equipment

#87
post #17

Earlier quoted context omitted.

Intel ME _is_ a backdoor. The funny thing is that there are many more. Interesting how the EU is dealing with this - most media seems to focus on how badly china could be spying while the US proved they aren't trustworthy long before.

Pretty obvious how the EU will deal with it. I once read the official statement of the German government that there is no way the US is spying on us while walking past dozens of huge radomes on a US base close to ESA hq. I read the news when it was discovered that our intelligence service regularly updated NSA selectors to spy on internet users and never looked into what they were updating. Suddenly they "found out"…

ESA headquarters is listed as in Paris. I'm not seeing any US bases near Paris. Orly used to be a US base but was shutdown in 1967 and is now a civilian airport.

Re: Vodafone Found Hidden Backdoors in Huawei Equipment

#88
post #18

As Jon Gruber says: "Bloomberg, of course, is the publication that published “The Big Hack” in October — a sensational story alleging that data centers of Apple, Amazon, and dozens of other companies were compromised by China’s intelligence services." "The story presented no confirmable evidence at all, was vehemently denied by all companies involved, has not been confirmed by a single other publication (despite much…

Bloomberg publishes what thousands of articles a year. Some percentage of them are guaranteed to be wrong. That doesn't meant that the burden of truth should instantly shift towards them being untrustworthy based on a single article. Journalism depends on the public trusting them and in the current environment in which that trust is being eroded to have comments like this that dismiss Bloomberg entirely is reckless a…

> being untrustworthy based on a single article

A single article... and the negative to do anything about it.

Yes it does.

Re: Vodafone Found Hidden Backdoors in Huawei Equipment

#89
post #64

Earlier quoted context omitted.

I swapped out China for US, Huawei for Google/Apple/Amazon/Facebook, Asian for South American, and it all still made sense.

US is a democracy with an independent judiciary. China isn't. Google, Apple etc are public companies. Huawei is state controlled. So it only makes sense if you completely ignore the basic facts.

> Google, Apple etc are public companies. Huawei is state controlled.

Citation needed - Huawei denies being under state control and there is no evidence of any direct state involvement in their day-to-day decisions. Maybe the Chinese state makes secret demands of them occasionally - but maybe the US state makes secret demands of Google/Apple occasionally.

Re: Vodafone Found Hidden Backdoors in Huawei Equipment

#90
post #45

I was skeptical about "boycotting" China and Huawei for a long time; just thought that they make cheap phones, and innovative tech, so why not. I changed 180 degrees when I started learning about the growing Chinese influence, how politically corrupt they are, and the excessive violence and human rights violations exercised against minorities. China is growing its economic dominance very quickly. They are gaining man…

"Chinese influence, how politically corrupt they are, and the excessive violence and human rights violations exercised against minorities." I know your heart is in the right place, but you could replace China with "The US" or "Russia" or "North Korea" or "colonial Britain" or almost any other country and it would be true. Those who wouldn't be worthy of the list are those who've never had the resources or opportunity…

[flagged]
Post reply on HN