And this is why I handroll my own routers/firewalls, using commodity hardware and a Linux distribution.
Tenda firmware (multiple versions) contains hidden authentication backdoor
41–50 of 136 posts
Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#42The US/Israel would never do such a thing, buy UniFi/Fortinet/Palo Alto!
There was a meme going round of a network diagram that layers a Chinese firewall behind a US firewall behind a Russian firewall so they can all block each other countries backdoors.
Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#43Earlier quoted context omitted.
Sounds like a convenience feature for a dev that they forgot to remove before distribution, since it's this poorly hidden.
In computer security, never attribute to ignorance that which is adequately explained by malice.
“Never attribute to malice that which is adequately explained by stupidity.”
Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#44And this is why I handroll my own routers/firewalls, using commodity hardware and a Linux distribution.
Looking to do this to get off stock isp leased router. What's your hardware/distro rec?
I wouldn't buy new hardware. Any modest machine built in the last decade would do. If possible, get a machine with an internal ATX power supply rather than an external brick, they tend to be more reliable.
If all you need is 1Gpbs and WiFi, OpenWrt on consumer hardware is probably enough though.
Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#45The US/Israel would never do such a thing, buy UniFi/Fortinet/Palo Alto!
Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#46Earlier quoted context omitted.
In computer security, never attribute to ignorance that which is adequately explained by malice.
You’ve got the saying backwards: “Never attribute to malice that which is adequately explained by stupidity.” https://en.wikipedia.org/wiki/Hanlon%27s_razor
Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#47My ifconfig is simple: if it's made in Shenzhen, throw it out
Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#48Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#49Earlier quoted context omitted.
You’ve got the saying backwards: “Never attribute to malice that which is adequately explained by stupidity.” https://en.wikipedia.org/wiki/Hanlon%27s_razor
Pretty sure the point was to invert it. :)