I don't get all the controversy over Huawei code having backdoors. Has anyone *looked*? I have. It's a humongous pile of buggy NIH. It doesn't *need* backdoors. It's guaranteed to have exploitable bugs. The Chinese govt just needs the source to find them faster than adversaries.
-
Show this thread
-
I looked at some of their switch firmware. It's got gems like a DIY SSH server implementation that leaks one half of the entire conversation to RAM, so scp'ing a firmware image or two OOMs and crashes the entire switch. DIY secondary TCP/IP stack. Internal backdoor FTP server.
3 replies 81 retweets 224 likesShow this thread -
Replying to @marcan42
Could you tell us which switch you have tested, please?
1 reply 0 retweets 1 like -
Replying to @paullovinicius
Forgot the exact model, but it was a 10gbase-t 1U 48 port model. We were evaluating vendors.
1 reply 1 retweet 3 likes -
Replying to @marcan42
The 5720 and 6720 are very good and have a low price compared to Cisco ones. I think it may be one of these. Thx!
1 reply 1 retweet 1 like
Yeah, 6720 looks about right. I'm sure a lot of their lineup uses the same software stack though, with the same bugs.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.