5 ms·
Why do they need a back door when they can walk right in through the front door? I used to work for a large company that purchased Huawei 4G gear and had a pai
by offmycloud 7y ago
Why do they need a back door when they can walk right in through the front door? I used to work for a large company that purchased Huawei 4G gear and had a paid support agreement. A condition of the agreement was giving VPN and SSH access to Huawei support engineers, so that they could "debug" their products in our network.
- drummer 7y agoIt would not surprise me if they also had some hardcoded accounts and certificates for convenient "support" access.
- mycall 7y agoadmin/admin
- kube-system 7y agoactually, it's root/admin for this device: http://manuals.zedt.eu/Huawei%20HG8245%20backdoor%20and%20remote%20access.pdf http://manuals.zedt.eu/Huawei%20HG8245%20backdoor%20and%20re...
- tastroder 7y agoAre we talking about Huawei or Cisco here? The well documented general stupidity of infrastructure hardware suppliers hardly supports the air quotes, or any of the nation state narratives here.
- drummer 7y agoSometimes it is convenient to disguise back doors as general stupidity or honest mistakes.
- reaperducer 7y agoWhy do they need a back door when they can walk right in through the front door? Because when one is discovered you use the other? Redundancy is a hallmark of good systems.
- kube-system 7y agoThe ideal strategy for an adversary is to not implement the backdoor while you have still front-door access and people are watching. Then you get 100% deniability. You wait to implement it until you think you're about to lose front-door access.
- tomc1985 7y agoIsn't it likely there'd be extra scrutiny on anything you do if you think you're about to lose front-door access?
- kube-system 7y agoThe people in the position to scrutinize likely wouldn't be the same ones to close the door, in this instance. Network carriers aren't going to turn down support for a support contract they paid good money for unless they have a good reason. If you put the backdoor in too soon, you get caught and you never get your devices implemented in the first place. But once you're in, the money for alternatives have already been allocated.
- dclusin 7y agoPlausible deniability most likely. They can give a private key to someone or leave a default login somewhere and claim ignorance.