Especially after seeing that "root
mydevice" string in the code, I think there's much to be said for this in relation to today's world of locked-down devices which resist control from even their owners. Given that their SoCs are meant for such devices, maybe it's AllWinner (or someone at the company)'s way of rebellion against that. If so, I'm glad that there are still people out there who do not believe in the user-oppressing culture of "security" that seems to have become the norm and are actually trying to do something about it. Maybe it really was just a debugging oversight, but either way, I'm not outraged by it --- contrary to what the media seems to say. This is a
local privilege escalation for software intended to run on a device that you --- and only you --- are supposed to own anyway.
Relatedly, here is a post 6 years ago by someone putting in a root backdoor in a device he designed --- and explaining how to use it:
http://www.bunniestudios.com/blog/?p=1140
If that was today, someone would discover it, scream "backdoor! security vulnerability!", and it would be all over the news like this one. And that makes me very sad.