Live data from Hacker News

Vodafone Found Hidden Backdoors in Huawei Equipment

bloomberg.com

91–100 of 131 posts

Re: Vodafone Found Hidden Backdoors in Huawei Equipment

#91

Earlier quoted context omitted.

Bloomberg publishes what thousands of articles a year. Some percentage of them are guaranteed to be wrong. That doesn't meant that the burden of truth should instantly shift towards them being untrustworthy based on a single article. Journalism depends on the public trusting them and in the current environment in which that trust is being eroded to have comments like this that dismiss Bloomberg entirely is reckless a…

> That doesn't meant that the burden of truth should instantly shift towards them being untrustworthy based on a single article. How many very high-profile articles need to be complete bullshit before it's time to start questioning the integrity of Bloomberg? The Supermicro nothing-burger was supposedly the culmination of a year of effort by top-shelf journalists. They knew what they were doing, they had NOTHING to s…

a) We don't know if the article is bullshit.

b) You have no evidence that that they didn't have sources, no evidence that they have ulterior motives and no evidence that they published the article without evidence.

c) Like you said if it was a year of effort by top-shelf journalists surely there is more to the story than simply "nothing".

Re: Vodafone Found Hidden Backdoors in Huawei Equipment

#92
post #89

Earlier quoted context omitted.

US is a democracy with an independent judiciary. China isn't. Google, Apple etc are public companies. Huawei is state controlled. So it only makes sense if you completely ignore the basic facts.

> Google, Apple etc are public companies. Huawei is state controlled. Citation needed - Huawei denies being under state control and there is no evidence of any direct state involvement in their day-to-day decisions. Maybe the Chinese state makes secret demands of them occasionally - but maybe the US state makes secret demands of Google/Apple occasionally.

US companies comply with laws governed by an independent judiciary and monitored by a free press.

China has none of those.

Re: Vodafone Found Hidden Backdoors in Huawei Equipment

#93

As opposed to backdoors in: - The SIM card for remote operator app provisioning. - The baseband processor (that supports over-the-air fireware updates, "typhoon boxes", and other horrible crap) - The GSM spec, lulz (that allows for binary SMS app pushes signed by certain keys, "silent" SMS to track location, and so on by protocol standard.) - Obsolete, broken, and purposefully weakened crypto that remains in use for…

Not be mention being fined in multiple countries for shady marketing practices!

Re: Vodafone Found Hidden Backdoors in Huawei Equipment

#94
post #74
post #17

Earlier quoted context omitted.

Intel ME _is_ a backdoor. The funny thing is that there are many more. Interesting how the EU is dealing with this - most media seems to focus on how badly china could be spying while the US proved they aren't trustworthy long before.

You haven't worked for large companies have you? Intel ME is NOT a backdoor. It may have vulnerabilities, sure. But none explicitly put in there. It was designed for a specific purpose- troubleshooting enterprise computers. And it does that job amazingly well. No more IT guy guiding me when he can just do all the clicks himself.

A backdoor is access to a computer which the legitimate owner cannot control. Intel ME fits this very well. Let me switch it off (verifiable) and we can talk.

If it was for troubleshooting enterprise computers, it would be opt in. At this point I assume bad faith.

Re: Vodafone Found Hidden Backdoors in Huawei Equipment

#95

>Vodafone said in the report that Huawei would need to remove or inhibit a so-called telnet service—a protocol used to control devices remotely—that the carrier said was a backdoor giving Huawei access to sensitive data. This seems like a diagnostic telnet port left open by accident. I'm very sceptical at this point at any American government or media finding a 'backdoor' in Huawei. A backdoor implies this is intenti…

It's not just American government or media who are wary of Huawei.

It's EU, Japan, Australia, New Zealand, Canada, UK etc.

Re: Vodafone Found Hidden Backdoors in Huawei Equipment

#96
post #12

Earlier quoted context omitted.

> Europe’s biggest phone company identified hidden backdoors in the software that could have given Huawei unauthorized access to the carrier’s fixed-line network in Italy, a system that provides internet service to millions of homes and businesses I think it is enough to be called a "backdoor".

A backdoor is a deliberate remote-access vulnerability that the creator intended to use for illegitimate access. The same code, but intentional, is a bug and vulnerability, but not a backdoor. Same security implications, but a big difference wrt. culpability, appropriate punishment, and expectations of future behavior.

>A backdoor is a deliberate remote-access vulnerability that the creator intended to use for illegitimate access.

I beg to differ. A backdoor gives access which the legitimate owner cannot control. I don't mind any intention.

Re: Vodafone Found Hidden Backdoors in Huawei Equipment

#97

>Vodafone said in the report that Huawei would need to remove or inhibit a so-called telnet service—a protocol used to control devices remotely—that the carrier said was a backdoor giving Huawei access to sensitive data. This seems like a diagnostic telnet port left open by accident. I'm very sceptical at this point at any American government or media finding a 'backdoor' in Huawei. A backdoor implies this is intenti…

I have been playing VikingMUD for more than a decade. I have been 'backdoor/hacking' it when I was using telnet to connect?

I have been audit in IT/IT Audit/IT Security for quite a while. Having ability to telnet in is not a crime. We got firewalls for stuff like that. Even if it is not documented in whatever paperwork have been provided, it takes 5 seconds on a scan to pick this up. There also a bunch of IDS/IPS out there that would spot and kill such a connection attempt in a millisecond.

Also, telnet is unencrypted. Who attacks something when everything is readable? It beats the purpose.

This story has so many holes that a junior net-admin could prevent in their first week. I will assume that Vodafone has 'an army' of highly skilled network and security administrators that have "block telnet" in the first page of their checklists.

I am not taking sides. I am just thinking of ways I have reacted in the past when I found on firewall logs blocked connect attempts.

I also think Bloomberg should stick to what they do best, money. Let the IT Sec to far more qualified outlets. Or if they really want to do this right, and not just aim for clickbaits, get a team of experts to go through their material before they post.

Re: Vodafone Found Hidden Backdoors in Huawei Equipment

#99

Earlier quoted context omitted.

Ah, but the article said that the telnet server "could still be launched," not that it was necessarily open. It could be one of those "magic knock" packets that 'launches' telnet, like the backdoor found in some Cisco routers a while back. Also weird is that Huawei insisted on keeping it open until they'd completed testing... does that mean it's phoning home? Or that they have their own technicians coming around to s…

"Never attribute to malice that which is adequately explained by stupidity" Some lazy engineer probably added the feature as a remote monitoring/debugging tool with no regard for security because it needed to work before the next big release. Disabling the feature before the next release would probably break all kinds of support and monitoring, potentially leading to instability or them being unable to service failin…

Thankfully not all of us take your approach.

Because you should always assume malicious intent when it comes to IT security.

Re: Vodafone Found Hidden Backdoors in Huawei Equipment

#100

Earlier quoted context omitted.

> That doesn't meant that the burden of truth should instantly shift towards them being untrustworthy based on a single article. How many very high-profile articles need to be complete bullshit before it's time to start questioning the integrity of Bloomberg? The Supermicro nothing-burger was supposedly the culmination of a year of effort by top-shelf journalists. They knew what they were doing, they had NOTHING to s…

a) We don't know if the article is bullshit. b) You have no evidence that that they didn't have sources, no evidence that they have ulterior motives and no evidence that they published the article without evidence. c) Like you said if it was a year of effort by top-shelf journalists surely there is more to the story than simply "nothing".

    > ...there is more to the story than simply "nothing".
Well, where is it? Seriously, where?

Bloomberg made the assertion, a serious one that moved markets, and now it's on them to prove it. Or at least someone needs to step forward with something that remotely corroborates the story.

It's a hard-to-believe claim on a technical basis alone like something straight out of James Bond story. It was a year in the making and now approaching 5 months later and still nothing?

Post reply on HN