TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Secret backdoor found in networking gear perfect for government espionage

4 pointsby kushtiabout 6 years ago

2 comments

theamkabout 6 years ago
&gt; .. allow an unauthenticated, remote attacker to connect to the affected system with the privileges of the root user.<p>&gt; The vulnerability is due to the presence of a default SSH key pair that is present in all devices.<p>That&#x27;s quite a bug -- I expected to see obscure exploit deep in the networking code which masterfully bypasses all code hardening, but found a default credentials instead. This is the kind of mistake that a random IoT company would do, I would not expect this from Cisco.
java-manabout 6 years ago
I don&#x27;t understand how this could happen in 2019. There were multiple people involved who coded, reviewed, tested the code, signed off on the release.<p>The other possible explanation is that it&#x27;s intentional.