Live data from Hacker News

Tenda firmware (multiple versions) contains hidden authentication backdoor

kb.cert.org

121–130 of 136 posts

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#121
post #98
post #76

Earlier quoted context omitted.

Yes, and my point is that hasn’t been the case in my experience.

It's because you (like me) aren't quite as paranoid as security people are. Personally I couldn't sleep at night if I was security people. It's really a matter of context. Security people tend to only be involved when things are already nefarious where as boring old normal people like us see get to see the mundane everyday mistakes so not just the nefarious bits.

> It's because you (like me) aren't quite as paranoid as security people are.

I work heavily with security-conscious clients where vulnerabilities would be catastrophic. And we are talking high profile clients that are juicy target for attacks.

My experience is still that the vast majority of vulnerabilities are accidental rather than due to malice.

And when I say “vast”, I mean the so heavily slanted in favour of “unintended” that it’s not even comparable.

> It's really a matter of context. Security people tend to only be involved when things are already nefarious

I’m guessing you’ve not worked with many “security people”?

You’d be surprised how much of their day-to-day is mundane.

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#122
Was that admin password intended for internal testing but ended in prod?

"Unfortunately, we were unable to reach the vendor"

With the widespread adoption of Tenda products in my local area, someone can have a good time exploiting this vulnerability.

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#123
post #105

Earlier quoted context omitted.

Backdoors are often (almost always?) designed to look like incompetence so that there's plausible deniability.

That sounds like a fun thing to wonder about, but how could anyone possibly know that for sure?

[flagged]

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#124

Earlier quoted context omitted.

Whatever these happen it's 50/50 either an internal debugging feature used when designing the device or intended as a way for customer support to more easily help people. I remember when a backdoor was discovered in the most popular brand of keylogging devices[0], likely added there in case someone forgot their password and reached out to support. [0] https://old.reddit.com/r/cybersecurity/comments/jw6k5v/backd...

> a way for customer support to more easily help people This is my guess. People don't like it when a device they have turns into a brick of e-waste because they can't remember their password. So most consumer devices have either a "reset to defaults" feature or a hidden support password. Even enterprise routers and switches often have this.

> So most consumer devices have either a "reset to defaults" feature or a hidden support password.

One of those is sensible, and one is not. Put a recessed "hold to reset" button on the device, problem solved, no backdoor required or desired.

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#125

Earlier quoted context omitted.

I mean, it's 99% sure this was supposed to be a debug feature...

Whatever these happen it's 50/50 either an internal debugging feature used when designing the device or intended as a way for customer support to more easily help people. I remember when a backdoor was discovered in the most popular brand of keylogging devices[0], likely added there in case someone forgot their password and reached out to support. [0] https://old.reddit.com/r/cybersecurity/comments/jw6k5v/backd...

> Whatever these happen it's 50/50 either an internal debugging feature used when designing the device or intended as a way for customer support to more easily help people.

The problem with this is, everyone who builds an intentional backdoor will also claim that it's this.

Sufficiently advanced ignorance is indistinguishable from malice, and sometimes needs to be treated as if it were malice.

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#127
post #105

Earlier quoted context omitted.

Backdoors are often (almost always?) designed to look like incompetence so that there's plausible deniability.

That sounds like a fun thing to wonder about, but how could anyone possibly know that for sure?

That's what makes it plausible deniability.

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#128
post #15

Have used their travel wifi product back when hotel wifi was a strange beast. Wouldn't expect to need it now eSIM and ubiquitous internet travel pricing means the hotel wifi may be the LEAST valid path to access things. I have a free give-away mikrotik unit in the same price bracket (literally free: they were both conference give-aways) it's physically smaller and it runs what appears to be their mainline code. Say w…

I’m working on a hotel right now. And I’ve gone to great lengths to make the wifi more secure. Everyone on their own VLAN. Separate PPSK for each room. Credentials are randomly generated and not some ridiculous pattern of last name and room number or similar. We built our own custom access control system, with what at the time was the strongest keycards we could find (mifare desfire ev3), I’m really trying to make a…

What fun is that? It used to be fun to `net send` little notes to strangers in hotels.

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#129
post #98

Earlier quoted context omitted.

It's because you (like me) aren't quite as paranoid as security people are. Personally I couldn't sleep at night if I was security people. It's really a matter of context. Security people tend to only be involved when things are already nefarious where as boring old normal people like us see get to see the mundane everyday mistakes so not just the nefarious bits.

> It's because you (like me) aren't quite as paranoid as security people are. I work heavily with security-conscious clients where vulnerabilities would be catastrophic. And we are talking high profile clients that are juicy target for attacks. My experience is still that the vast majority of vulnerabilities are accidental rather than due to malice. And when I say “vast”, I mean the so heavily slanted in favour of “u…

Oh i've worked with plenty. Maybe they knew more than they let on but they were (and are) convinced that every little belch is a full on attack.

I know their day to day is just as mundane as the rest of ours it's their "Step 1" approach that i've seen to be entirely different. I assume it's probably a software bug, they assume it's an exploit.

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#130
post #129

Earlier quoted context omitted.

> It's because you (like me) aren't quite as paranoid as security people are. I work heavily with security-conscious clients where vulnerabilities would be catastrophic. And we are talking high profile clients that are juicy target for attacks. My experience is still that the vast majority of vulnerabilities are accidental rather than due to malice. And when I say “vast”, I mean the so heavily slanted in favour of “u…

Oh i've worked with plenty. Maybe they knew more than they let on but they were (and are) convinced that every little belch is a full on attack. I know their day to day is just as mundane as the rest of ours it's their "Step 1" approach that i've seen to be entirely different. I assume it's probably a software bug, they assume it's an exploit.

> I assume it's probably a software bug, they assume it's an exploit.

They're not mutually exclusive.

I suspect you and the security team are arguing the same thing but with different terminology.

When vulnerabilities (which, in the vast majority of cases, are accidental) are published, or when static analysis tools review code, you'll get a description and a severity score. That description will broadly describe how, if possible, that vulnerability can be exploited.

Working for an in-house security team basically just means you're a risk assessor. And the way you assess risks is to look at the potential consequences of those risks. Which means looking at how bugs can be exploited.

But none of this means those vulnerabilities were placed in the code intentionally and with malice. It just means that someone else who is malicious could, theoretically, exploit those vulnerabilities. And if the risk of that is greater than the risk appetite of the business (as will typically be the case), then they'll feedback to you that there is an exploitable vulnerability that you need to patch.

Post reply on HN