Live data from Hacker News

Tenda firmware (multiple versions) contains hidden authentication backdoor

kb.cert.org

41–50 of 136 posts

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#42
post #16

The US/Israel would never do such a thing, buy UniFi/Fortinet/Palo Alto!

There was a meme going round of a network diagram that layers a Chinese firewall behind a US firewall behind a Russian firewall so they can all block each other countries backdoors.

https://en.wikipedia.org/wiki/Swiss_cheese_model

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#43
post #39

Earlier quoted context omitted.

Sounds like a convenience feature for a dev that they forgot to remove before distribution, since it's this poorly hidden.

In computer security, never attribute to ignorance that which is adequately explained by malice.

You’ve got the saying backwards:

“Never attribute to malice that which is adequately explained by stupidity.”

https://en.wikipedia.org/wiki/Hanlon%27s_razor

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#44
post #21
post #13

And this is why I handroll my own routers/firewalls, using commodity hardware and a Linux distribution.

Looking to do this to get off stock isp leased router. What's your hardware/distro rec?

Ryzen 5 with a dual 10Gbps NIC, running Debian. Overkill for a router/firewall, but I run other services on the same hardware including an email stack, Podman containers, and small AI model for use within Home Assistant.

I wouldn't buy new hardware. Any modest machine built in the last decade would do. If possible, get a machine with an internal ATX power supply rather than an external brick, they tend to be more reliable.

If all you need is 1Gpbs and WiFi, OpenWrt on consumer hardware is probably enough though.

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#45
post #16

The US/Israel would never do such a thing, buy UniFi/Fortinet/Palo Alto!

They'll have a lot of work to do, if they want to catch up with the amount and rate of "hidden authentication backdoors" all those companies (and also Cisco) have. E.g. https://www.thestack.technology/cisco-hard-coding-passwords-...

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#46
post #43
post #39

Earlier quoted context omitted.

In computer security, never attribute to ignorance that which is adequately explained by malice.

You’ve got the saying backwards: “Never attribute to malice that which is adequately explained by stupidity.” https://en.wikipedia.org/wiki/Hanlon%27s_razor

Pretty sure the point was to invert it. :)

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#48
post #13

And this is why I handroll my own routers/firewalls, using commodity hardware and a Linux distribution.

Tenda has good support among OpenWRT.

So the next step is a hardware or boot firmware backdoor?

(Good to know it remains useful by using openWRT and doesn't become landfill)

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#49
post #46
post #43

Earlier quoted context omitted.

You’ve got the saying backwards: “Never attribute to malice that which is adequately explained by stupidity.” https://en.wikipedia.org/wiki/Hanlon%27s_razor

Pretty sure the point was to invert it. :)

Yes, I got their point. My point is that’s the opposite of reality.

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#50
A quick search reveals several other serious vulnerabilities in Tenda routers that could grant administrator privileges. Therefore, I tend to believe this is due to the company's incompetence and lack of technical skill rather than malicious intent—but it's still a reason to avoid using Tenda products. There's a reason why Tenda's market share is far lower than TP-Link's.
Post reply on HN