Live data from Hacker News

Tenda firmware (multiple versions) contains hidden authentication backdoor

kb.cert.org

61–70 of 136 posts

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#61
post #49
post #46

Earlier quoted context omitted.

Pretty sure the point was to invert it. :)

Yes, I got their point. My point is that’s the opposite of reality.

His point is that in security, the opposite applies. The supposed "incompetence" is just plausible deniability for a malicious act.

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#63

The article doesn't disclose the value of "sys.rzadmin.password", but this writeup from 2022 does: https://boschko.ca/tenda_ac1200_router/ Spoiler: it's "rzadmin". And it looks like there are a bunch of other goodies in the firmware, too.

That backdoor is so up front about it. We might as well call it a frontdoor.

I mean, it's 99% sure this was supposed to be a debug feature...

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#64

> The associated username is not validated, so any provided username will succeed when paired with the backdoor password. Great. I am really wondering why should the customers trust these manufacturers. At this point I would not use any router with vendor-provided black box firmware. Full stop. I would always install OpenWRT or something similar on it before using it. And if that is not possible for whatever reason,…

[deleted]

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#65
I've seen it last night, and I was like wtf?! Frankly, if they tried to build in some backdoor, I bet they would have done it differently, not so obviously. This must have been some sort of stupidity done for testing purposes, and just got buried deep in the code and forgotten.

This is the main reason why you should always use OpenWRT or other opensource router OS. If it gets an issue, at least it would get patched in the next update.

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#66
post #49
post #46

Earlier quoted context omitted.

Pretty sure the point was to invert it. :)

Yes, I got their point. My point is that’s the opposite of reality.

Maybe it's time to take a closer look at reality and correct this meme, which might casually blur the issue and deflect responsibility?

Looking at the IT security landscape we see every layer, every product category if not every product itself riddled with issues at one point or another. At the same time the incentives to put those security issues in are huge, and we know attackers work systematic, creative and persistent to introduce those weak points.

Security is hard and many bugs certainly happen due to mistakes, but I wouldn't assume that all of those security mishaps stem from an endless series of blunders from "stupid" programmers.

So I would go with “Never attribute to ignorance that which is adequately explained by malice.”

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#67

The article doesn't disclose the value of "sys.rzadmin.password", but this writeup from 2022 does: https://boschko.ca/tenda_ac1200_router/ Spoiler: it's "rzadmin". And it looks like there are a bunch of other goodies in the firmware, too.

At that point it’s not even a back door it’s just stupid default root password kind of design which used to be standard in this kind of hardware. Backdoor would at least try to be subtle :)

Backdoors are often (almost always?) designed to look like incompetence so that there's plausible deniability.

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#68

> The associated username is not validated, so any provided username will succeed when paired with the backdoor password. Great. I am really wondering why should the customers trust these manufacturers. At this point I would not use any router with vendor-provided black box firmware. Full stop. I would always install OpenWRT or something similar on it before using it. And if that is not possible for whatever reason,…

good approach, but your security should not depend on your router anyway, you should be immune to attacks from it

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#69

Earlier quoted context omitted.

That backdoor is so up front about it. We might as well call it a frontdoor.

I mean, it's 99% sure this was supposed to be a debug feature...

and "accidentally" they forgot to disable it when releasing

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#70

> The associated username is not validated, so any provided username will succeed when paired with the backdoor password. Great. I am really wondering why should the customers trust these manufacturers. At this point I would not use any router with vendor-provided black box firmware. Full stop. I would always install OpenWRT or something similar on it before using it. And if that is not possible for whatever reason,…

Last time when I looked OpenWRT was unable to support MIMO and beamforming capabilities of many of the devices it was running on.

This capabilities are crucial to have decent coverage, signal strength and throughput where I live (i.e.: crowded/congested wireless networks in an apartment complex).

Did OpenWRT team managed to work around them, or did the manufacturers started to play nicer with open drivers with loadable firmware?

Post reply on HN