Live data from Hacker News

Huawei dev team submit Linux patch with backdoor, Huawei denies involvement

androidrookies.com

11–12 of 12 posts

Re: Huawei dev team submit Linux patch with backdoor, Huawei denies involvement

#11
post #2

Grsecurity people have been involved in a lot of fights and accusations over the years. Also this was a first posting of the patch set. I think it's pretty hard to show malice here. Of course your bayesian prior will be influenced by how paranoid you are about Huawei in general. edit: apologies to Grsecurity, as pointed out downthread they make no accusations of backdoors. Although apparently the Grsecurity blog post…

Actually if you read the grsecurity blog it is much more nuanced then the linked story (and would have been a much better source to link to IMO). In particular they do not insinuate a backdoor. In fact their post is pretty consistent in that they criticize the quality (or lack thereof) and limited understanding of security, which they have done for many others as well. This seems to really be a story blown out of pro…

Good correction.

But reading the Grsecurity blog, it becomes even clearer that this is far from production code and would be very far from passing any kind of QC for production code.

Re: Huawei dev team submit Linux patch with backdoor, Huawei denies involvement

#12

I wonder whether it's better just to link to grsecurity here https://grsecurity.net/huawei_hksp_introduces_trivially_expl...

>Based on publicly-available information, we know the author of the patch is a Huawei employee, and despite attempts now to distance itself from the code after publication of this post, it still retains the Huawei naming. Further, on information from our sources, the employee is a Level 20 Principal Security staffer, the highest technical level within Huawei.
Post reply on HN