ZTE confirms backdoor in U.S. phone(reuters.com)
reuters.com
ZTE confirms backdoor in U.S. phone
http://www.reuters.com/article/2012/05/18/us-zte-phone-idUSBRE84H08J20120518
4 comments
I feel that the word "backdoor" is incorrectly used here. ZTE confirmed a vulnerability discovered in the phone, not something they placed in the phone intentionally (backdoor).
In my mind, "backdoor" is a subset of vulnerability where an intentional permission escalation mechanism can be used in nefarious ways - hence making this a backdoor first and a vulnerability second.
I suspect the code was placed on the phone very intentionally for use by a non-nefarious update or sync agent, especially due to the name of the binary. Hence, a backdoor - just not the "OMG Chinese government watching us" tinfoil hat backdoor it's been made out to be.
I suspect the code was placed on the phone very intentionally for use by a non-nefarious update or sync agent, especially due to the name of the binary. Hence, a backdoor - just not the "OMG Chinese government watching us" tinfoil hat backdoor it's been made out to be.
How is a hardwired password to allow remote access a vulnerability rather than a backdoor?
Last analysis I saw, the access was not remote. It was a local root escalation; you need to have code running on the device before you can use it.
[deleted]
[deleted]
[deleted]
Is that this: http://news.ycombinator.com/item?id=3994054
Because yeah, this has been known for a while...
Because yeah, this has been known for a while...
Nope. Its this: http://news.ycombinator.com/item?id=3968041 from several days before your link.
Right, that's what I was saying. The ZTE problem has specifically been known... so if that employee posted that SO post ("my" link)... he probably found out about it via Reddit/HN, thus posting "anonymously" would have been rather silly.
Oh I see your point now. I'm not sure I'd assume so, probably just coincidental timing. It would seem pretty silly/pointless for your link's OP to ask advice on a (by then) publicly known exploit after all.
[deleted]
Let's just say that, generally speaking, Russian and Chinese companies work very differently from those in USA. If their "CIA" shows up and wants something added, you either add it or you may be out of business...and that's if they're feeling generous. You can't exactly file a whistle blower lawsuit or go public with the info.