Live data from Hacker News

Tenda firmware (multiple versions) contains hidden authentication backdoor

kb.cert.org

101–110 of 136 posts

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#101
post #78

Earlier quoted context omitted.

Looks like this time you interpreted the message in a malicious way.

How? Neither their comment nor mine have anything malicious in their tone nor content.

Unfortunately, explaining a joke won’t make it funny afterward I guess.

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#102
post #79

Earlier quoted context omitted.

Last time when I looked OpenWRT was unable to support MIMO and beamforming capabilities of many of the devices it was running on. This capabilities are crucial to have decent coverage, signal strength and throughput where I live (i.e.: crowded/congested wireless networks in an apartment complex). Did OpenWRT team managed to work around them, or did the manufacturers started to play nicer with open drivers with loadab…

Some routers specifically allow openWRT.. example, Routers like the GL.iNet GL-MT6000 (Flint 2) and TP-Link Archer AX6000 come with OpenWrt pre-installed and are designed for easy OpenWrt use.

...usually because they have a fork of the codebase, and it's not vanilla base OpenWRT.

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#103
post #98
post #76

Earlier quoted context omitted.

Yes, and my point is that hasn’t been the case in my experience.

It's because you (like me) aren't quite as paranoid as security people are. Personally I couldn't sleep at night if I was security people. It's really a matter of context. Security people tend to only be involved when things are already nefarious where as boring old normal people like us see get to see the mundane everyday mistakes so not just the nefarious bits.

[deleted]

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#104
post #53

The consistency with which networking hardware companies produce such garbage is crazy. And it’s always amateur hour backdoors somehow. If it was something sophisticated they might get a pass on „ok some security agency made them do it probably“

Sad truth is that too few customers pay extra for proper security. And even then it is questionable will you get it.

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#105

Earlier quoted context omitted.

At that point it’s not even a back door it’s just stupid default root password kind of design which used to be standard in this kind of hardware. Backdoor would at least try to be subtle :)

Backdoors are often (almost always?) designed to look like incompetence so that there's plausible deniability.

That sounds like a fun thing to wonder about, but how could anyone possibly know that for sure?

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#106
Most of the software is this way, it seems. Military intelligenece in our country were recently changing configs on peoples routers without their knowledge or consent to get rid of similarly dangerous thing on several types of tp-link routers.

And if you ever looked inside the firmwares of these IoT Linux boxes (be it sip phones, payment terminals, ip cameras, routers, modems, etc.) you'd not want it anywhere near anything that needs to be secure. OpenWRT or your own thing, or very strict isolation, or nothing.

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#107

> The associated username is not validated, so any provided username will succeed when paired with the backdoor password. Great. I am really wondering why should the customers trust these manufacturers. At this point I would not use any router with vendor-provided black box firmware. Full stop. I would always install OpenWRT or something similar on it before using it. And if that is not possible for whatever reason,…

Hm, do you ever go over 1gbit? If my understanding is correct, good affordable routers like Mikrotik's CCR2004 are fully closed, so the only option is to build your own shitty box which will be much less energy efficient than their specialized switch chips.

> do you ever go over 1gbit

No. None of the local ISPs offer speeds above 1 Gbps.

However, I use FriendlyElec NanoPi R5C as the main entrypoint router. It has two 2.5G ethernet ports. It costs less than 100 euros. And it runs OpenWRT.

It is not a multiport, multi-gigabit device though. And I have not tested it above 1 Gbps so I am unsure about its real world performance.

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#108
post #98
post #76

Earlier quoted context omitted.

Yes, and my point is that hasn’t been the case in my experience.

It's because you (like me) aren't quite as paranoid as security people are. Personally I couldn't sleep at night if I was security people. It's really a matter of context. Security people tend to only be involved when things are already nefarious where as boring old normal people like us see get to see the mundane everyday mistakes so not just the nefarious bits.

I'm a security people. I can say with confidence that a tiny, tiny, tiny, tiny fraction of these security issues are deliberate. Almost all of them are just dumb mistakes because making good software is really hard and really, really expensive and there is no market incentive to make good software. You don't need to get hired at the safe factory to build an elaborate back door into the production line if safes are actually just cardboard boxes, you know?

It's possible the backdoor is deliberate, I have no idea in this particular case, but the more likely situation, absent more information, is that someone who is earning a middling wage just added the "feature" and didn't think about the security implications because no one cares about computer security.

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#109
post #43
post #39

Earlier quoted context omitted.

In computer security, never attribute to ignorance that which is adequately explained by malice.

You’ve got the saying backwards: “Never attribute to malice that which is adequately explained by stupidity.” https://en.wikipedia.org/wiki/Hanlon%27s_razor

[deleted]

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#110

The article doesn't disclose the value of "sys.rzadmin.password", but this writeup from 2022 does: https://boschko.ca/tenda_ac1200_router/ Spoiler: it's "rzadmin". And it looks like there are a bunch of other goodies in the firmware, too.

Somehow this reads like German to me. Because "rz" is a common abbreviation of RechenZentrum, meaning DataCenter.

So in English it would be like "dcadmin". Maybe they outsourced it to someone doing "gute Deutsche Wertarbeit", or it's a leftover from some agency having had their fun, or smoke&mirrors from whomever for whichever reasons.

Post reply on HN