NSA-style backdoor in Huawei laptops found by Microsoft
scmagazineuk.com
scmagazineuk.com
https://www.microsoft.com/security/blog/2019/03/25/from-aler...
Privilege escalations aren't that rare unfortunately. Kind of cool that ATP might be able to detect some of them going forward, particularly in drivers that are often black-boxes.
For it to be a backdoor it would typically need to facilitate the ability to access the system itself (e.g. Remote code execution, hidden credentials, etc), but even then intent is implied with the word which we simply don't have here.
Plus it LPEs aren't as powerful as they once were. Most of the good stuff is now running in userspace, the only thing a LPE grants you is persistence.
To give you an idea of how overblown this is: HP used to run a local webserver as SYSTEM (highest priv) which any webpage could call via iFrame to execute local commands. I don't consider that a backdoor either, even though that issue is ten times more serious than this one.
>"We traced the anomalous behaviour to a device management driver developed by Huawei," researchers said in the post. "Digging deeper, we found a lapse in the design that led to a vulnerability that could allow local privilege escalation."
>Researchers who reported the vulnerability to Huawei said the company responded and cooperated quickly and professionally. A patch was released earlier this year on 19 January.
A rather clickbait-y title for what actually happened. Of course though, rehashed old news is great for harvesting karma when it's the right bogeyman.
Reminding us once again that as far as has been documented in the open media the US is the only country that has been identified as having done this.
Sadly this is Tony Morbin's modus operandi.[1]
That said, two nice takeaways, one the standard tools that Microsoft shipts found a problem, and the vendor quickly patched it. Both of those things are good news.
A good way to inject a backdoor is to discourage the fixing of poorly designed drivers. I'm certain the NSA has a vast collection of vulnerabilities they exploit to do their work, who would be surprised if they didn't at least once try to discourage the fixing of one of those bugs.
Just in case you hadn't already seen this:
It’s especially hilarious that Mr. Campbell was accused of being a conspiracy theorist for thinking _NSAKEY would be exactly what it sounds like.
Even better, it turns out the key WAS for the NSA (!) “because the NSA is the technical review authority for U.S. export controls.” How convenient.
Sorry I’m not buying it. I worked in .gov contracting long enough to smell a cover story.
The whole NSAKEY story is a laughable fabrication, nobody has ever described the mechanism by which the backdoor is supposed to work. This should be a trivial exercise.
https://www.microsoft.com/security/blog/2019/03/25/from-aler...
If Huawei wanted to do this the smart way they would implement a backdoor that's VERY tough to find but could also be justified by stupidity.
This way they have plausible deniability.
"We're not malicious. We just screwed up!"
If it was obvious the Chinese government did this, then other world governments would have to respond with sanctions and import bans.
That being said, there is value in a LPE as a part of a bigger exploit chain. There's all sorts of exploits that'll give you relatively unprivileged code execution, and you'd want to silently elevate in order to make yourself persistent for instance.
Like I said, I think this is just a bug, but Windows LPEs do have value.
Then when someone says: "Huawei pwns us", they can just claim ignorance and stupidity because a small mistake here and there provides better deniability than some whitehat finding out that Huawei provides the Chinese government with the whole set of keys to the kingdom.
The Snowden files said nothing about Intel’s ME. That isn’t a backdoor either. It’s a great place to put one, but there are lots of great places to put backdoors, and that doesn’t mean that’s what the manufacturer is doing.
There have been cases where specific things were targeted. This isn’t even close to every piece of hardware.
“There are no mistakes” is a ridiculous notion for anyone who has ever had a career tangentially related to software or hardware. I don’t know how someone who holds this viewpoint even managed to find this website. You really don’t think bugs ever happen by accident?
This is a great website for freely expressing opinions, truth, lies and such!
Peace be with you.
Do you have any examples?
So what, you want proof that the backdoor is deliberate? To do that, you'd either need some sort of internal directive from up top (good luck finding that), or the backdoor was comically bad (eg. if (signed by PLA) return true;).
If the title of the article is "backdoor found", then yeah. I'm of the opinion that it was an intentional backdoor too, I think that was a pretty clear possibility to anyone who saw the initial writeup. But to come out and claim unambiguously that it was a backdoor is masquerading an opinion as news.
It would be more entertaining if I thought other vendors were less likely to be compromised[1].
[1] https://www.wired.com/2015/12/researchers-solve-the-juniper-...
Seems like a very reasonable request.
The strictly local nature of this "backdoor" strongly suggests that it is not in fact a backdoor, if you're going to call it a backdoor maybe you should have the least bit of evidence to support that.
If the US security sector blew the lid on the backdoors, they would also be exposing their own backdoors, thus all they can do is generate FUD towards Huawei, and hope that they never need to present evidence.
a) Trade war
b) Chinese boogeyman makes US companies look better?
The double-think of the rhetoric against Huawei is staggering considering US programs like Prism were state-mandated data collection at a massive scale against private citizens and a secret courts program to access private sector companies data on those same citizens.
A Dakota Pipeline Protests journalist was stopped at the US border, "raising press freedom alarms."(1) Laura Poitras, Greenwald, Ladar Levison have been obviously victims of ill will from US authorities. Of course, don't forget the "get Gary Webb team" of industry experts the CIA watched over, which set out to "we're going to take away his Pulitzer."(2) Non-radical political parties are swat raided, intimidated, and silenced by secret courts in the US(3).
Of course this is just the start to a very long list. But comments which suggest everything is fine in this regard really worry me, as someone who loves America and its values.
1-https://www.nytimes.com/2016/12/02/business/media/canadian-j...
2-https://theintercept.com/2014/09/25/managing-nightmare-cia-m...
[edit] to clarify about the "disengenous" part. It's not about saying "This is bad", it's about saying "This is bad, we would never do anything like that, can you believe it, what evil people" when in fact it is something you do, or have done, and given the chance will probably do again. This obviously doesn't cover all of the bad behavior of Chinese govt, but it certainly does some.
Saying "we caught out country X doing something we don't like but also do to them" maybe doesn't have the same ring to it, but has the advantage of being honest.
Or are you advocating for a constant apologizing for US misdeeds any time another countries' misdeeds are raised, even if that other countries' are far worse...?
Actually I'd rather we avoid the whole pointless whataboutism exercise if we can.Again, it's not either or. The originating comment was claiming that some of the news about Huawei is being driven by very different motivations (I think it was trade war fallout), and being stated in disingenuous ways. And yes, there seems a lot of pearl clutching going on right now about vaguely defined Chinese technology threats. As well as some very real concerns about Nation-state actors in this space, China in particular. That seems worth at least questioning.
What I am saying is that it is perfectly consistent to hold the mixture of views that the Chinese government is doing some really bad things with privacy and personal data, that the US government also does some really bad things with privacy and personal data (though not nearly as many as Chinese govt) and that some of what is being propagated in the media currently against companies like Huawei has very little to do with these things but rather is based more on domestic economic interests.
I think it's fair to call that last part out, without it devolving into a bunch of whataboutism on the former.
Agree that particular poster could have worded things better, but they had a (valid, I think) point.
It doesn't have to be doublethink. Even if the US gathers intelligence in ways that make one uncomfortable, China doing it to US citizens makes one _more_ uncomfortable.
In other words, the US doing it doesn't make China doing it any better.
If I'm running a company, I don't want Chinese spies backdooring my equipment, regardless if the NSA is effectively doing the same thing. At least the NSA isn't going to steal my data and give it to foreign business competitors.
To be fair, the US has a long history of hyping up a boogeyman for its own purposes.
The NSA has their useful idiots too.
Seriously, I'm not even surprised. Whether it's intentional or not doesn't matter. Huawei pays a lot for advertising to all popular laptop reviewers on Youtube. But I'm not even considering buying Huawei laptops because I'm pretty sure it's full of crap like this.
Also, while I'm at it, it would be nice if Unbox Therapy and other like it would make mention of the Botnet threat in their product reviews.
Do you expect Youtubers to have a top-class security team to reverse engineer firmware? This was discovered weeks/months later after the product was released.
Or do you want civil liability with substantial damages for every bug that might ever be exploited?
I have seen, though, many things that indicate that their dev practices just plain suck - and that alone is enough for me not to buy their products.
EDIT: Also, that's a major false equivalence.
Deniability I guess. I guess US intel yelling at the top of their lungs this has and will happen isn't enough for some.
This is exactly what the Cambridge Analytica "scandal" is about. Individually, you may have nothing to hide, but in aggregate, the data is rather powerful.
[1] https://en.wikipedia.org/wiki/Psychological_warfare
I also just dug up another article about Big Data and PSYOPS.
https://www.nybooks.com/daily/2018/03/21/the-digital-militar...
Looks like China got him before he could finish typing
I care.
NSA has also been caught spying for economic purposes. They were spying on Brazilian oil giant Petrobras:
http://g1.globo.com/fantastico/noticia/2013/09/nsa-documents...
* Liberty
* Security