Live data from Hacker News

Cisco Nexus 9000 Switches Allow SSH As Root

nvd.nist.gov

41–50 of 113 posts

Re: Cisco Nexus 9000 Switches Allow SSH As Root

#42

Earlier quoted context omitted.

A backdoor to me suggests an intentional loophole through a level of security. A bug that does the same is severe, but isn't intentional. At least that's my reading.

But any competently inserted intentional backdoor is going to be indistinguishable from a mistake. If Cisco had some SecretFBIChinaBackdoor() function somewhere the backlash would be way way worse (or at least an unknown). Whereas at this point it's abundantly clear that serious "non intentional" security vulnerabilities in networking hardware basically go ignored by the market.

>But any competently inserted intentional backdoor is going to be indistinguishable from a mistake.

Maybe, but without proof it's still just speculation. Real bugs do occur often, and sometimes in sensitive areas.

I understand wanting to be vigilant. In both assuming malice and assuming human error though, you're still forced to make an assumption.

Re: Cisco Nexus 9000 Switches Allow SSH As Root

#47

Earlier quoted context omitted.

But any competently inserted intentional backdoor is going to be indistinguishable from a mistake. If Cisco had some SecretFBIChinaBackdoor() function somewhere the backlash would be way way worse (or at least an unknown). Whereas at this point it's abundantly clear that serious "non intentional" security vulnerabilities in networking hardware basically go ignored by the market.

>But any competently inserted intentional backdoor is going to be indistinguishable from a mistake. Maybe, but without proof it's still just speculation. Real bugs do occur often, and sometimes in sensitive areas. I understand wanting to be vigilant. In both assuming malice and assuming human error though, you're still forced to make an assumption.

You're not forced to make an assumption, you can just be honest and say you don't know. There's too many comments in this thread effectively saying "it looks unintentional, so it's unintentional".

Re: Cisco Nexus 9000 Switches Allow SSH As Root

#50
post #8

Earlier quoted context omitted.

It allows anyone who knows the default SSH key pair to login as root. How is that not a backdoor? Backdoor definition: "A backdoor is a method, often secret, of bypassing normal authentication in a computer system."

People sometimes read "backdoor" as something intentionally left by an insider for later use by themselves or others.

And what do you think this was? Virtually all router/networking devices have some kind of "hardcoded account" (read:backdoor) and this is only slowly changing. I believe the EU is going to ban the practice soon.
Post reply on HN