Live data from Hacker News

Huawei cryptographic keys embedded in Cisco’s firmware

iot-inspector.com

21–30 of 38 posts

Re: Huawei cryptographic keys embedded in Cisco’s firmware

#21

seeing this more and more... open source projects pulled in as dependencies without auditing, and causing a security issue. I predict this is going to become more and more of an issue over the next couple of years, and provoke some drastic changes to the way we do open-source software. What those changes are, I don't know...

While that observation might be true (I doubt it will change Open Source, nor is it a new problem), what's the security issue in this particular case? Cisco adding an already compromised (it's on GitHub) private key to their firmware, which sure isn't a smart thing to do. But the only security issue I could see here is that somebody could use it to create a "secure" outbound connection from a Cisco device, that just…

yes, in this instance it turned out to be "not an actual issue".

But no-one at Cisco seemed to be aware of it until alerted, and it was discovered by a product team looking specifically for IoT security vulnerabilities. It's clear that Cisco aren't auditing their third-party dependencies thoroughly. It could easily have been a vulnerability. They got lucky.

And yeah, it's not a new problem, but there does seem to be growing awareness of it, which is both good (because a solution will be found), and bad (because the bad people will be more aware of the opportunity).

Re: Huawei cryptographic keys embedded in Cisco’s firmware

#23

So, in summary: 1. Cisco used Open Source software (OpenDaylight), without sanitizing publicly available (GitHub) certificates and private keys. 2. The screenshot in the source article mentions the subject of the certificate. Yet, the text refers to it as the signing party. 3. Somebody used a business name and an email address that is associated to Huawei, to generate a certificate. Observations: - Regarding (1): If…

Yeah, the editorial titling was definitely clickbaity. That's why I always come to the comments first on HN if an article sounds sensationalistic.

Re: Huawei cryptographic keys embedded in Cisco’s firmware

#24

Tired: Cisco routers have U.S. backdoors! Fired: Huawei routers have Chinese backdoors! Inspired: Cisco routers have Huawei backdoors! Reality is often stranger than fiction...

No reality is usually boring. It came from an opensource github repo. It was an oversight. Dial down the conspiracy-factor brother.

If the dial of conspiracy was turned to low for the last few years, it's quickly moving into the hot position.

Re: Huawei cryptographic keys embedded in Cisco’s firmware

#25

So, in summary: 1. Cisco used Open Source software (OpenDaylight), without sanitizing publicly available (GitHub) certificates and private keys. 2. The screenshot in the source article mentions the subject of the certificate. Yet, the text refers to it as the signing party. 3. Somebody used a business name and an email address that is associated to Huawei, to generate a certificate. Observations: - Regarding (1): If…

Shoddy journalism, or compliance with an ongoing political narrative.

Re: Huawei cryptographic keys embedded in Cisco’s firmware

#26

Tired: Cisco routers have U.S. backdoors! Fired: Huawei routers have Chinese backdoors! Inspired: Cisco routers have Huawei backdoors! Reality is often stranger than fiction...

No reality is usually boring. It came from an opensource github repo. It was an oversight. Dial down the conspiracy-factor brother.

Often is not the same as usually.

Re: Huawei cryptographic keys embedded in Cisco’s firmware

#27

So, in summary: 1. Cisco used Open Source software (OpenDaylight), without sanitizing publicly available (GitHub) certificates and private keys. 2. The screenshot in the source article mentions the subject of the certificate. Yet, the text refers to it as the signing party. 3. Somebody used a business name and an email address that is associated to Huawei, to generate a certificate. Observations: - Regarding (1): If…

Shoddy journalism, or compliance with an ongoing political narrative.

This is a blog post by the software company that discovered the issue.

It's simply a marketing team leveraging the current threat environment to raise the profile of their product.

Re: Huawei cryptographic keys embedded in Cisco’s firmware

#28

Tired: Cisco routers have U.S. backdoors! Fired: Huawei routers have Chinese backdoors! Inspired: Cisco routers have Huawei backdoors! Reality is often stranger than fiction...

No backdoor this time, but a private (!) key.

No idea what the private key is used for, but doesn't look like you can use it to log into the device.

Re: Huawei cryptographic keys embedded in Cisco’s firmware

#30
> Who is gary.wu1(at)huawei.com, and why are his keys embedded in Cisco’s firmware?

.. and, lastly, why the do we care about protecting his e-mail address from harvesters with (at) if he so loose with it himself that he lets it end up in random firmware?

Post reply on HN