China spied on Dutch Cyber Intelligence through FortiGate backdoors
defensie.nl
defensie.nl
> The malware found installed a ‘backdoor’ by using a known vulnerability in FortiGate devices. The publication of the MIVD therefore does not describe any new vulnerability in all FortiGate devices.
I could believe factory backdoors in Fortinet products, including bugdoors, but it's even easier to believe commonplace unintended software defects.
Edit: This comment was a response to the HN title "China spied on Dutch Cyber Intelligence through FortiGate backdoors (defensie.nl)". I thought people will tend to interpret "FortiGate backdoor" as meaning an intentional backdoor by the vendor/factory, when that's not what the article seemed to suggest.
Note the fact that this was actively exploited by the Chinese. That sort of reduces the chance of this being an accident, especially since they've done this before.
Occasionally, a proven intentional vulnerability will happen, so we want to be careful not to cry wolf other times.
It's reasonable to be cautious about Fortinet in general, but I don't think the fact that a known vulnerability was exploited suggests that the vulnerability was intentional.
Is a bugdoor a factory backdoor implemented via an intentional bug?
Is the idea to give plausible deniability if the backdoor gets found?
The first time I heard the idea, someone was claiming publicly that a manager/lead at a tech vendor had been approached by a government, and asked to insert a backdoor that would look accidental, and without the larger organization aware. That might've been apocryphal, but the idea was plausible.
The idea is maybe received a bit differently today, when there's a ton more people doing work, by a ton of developers who haven't had correctness and security prioritized. Even some of the key bits of tech infrastructure, by some the largest tech companies, seem to think weekly security updates, for multiple CVEs each, isn't insane. "Uh, you want us to make a security vulnerability, and make it look like it was because we were negligent? If you can wait a week, I can give you a dozen all-natural ones."
https://www.ncsc.nl/binaries/ncsc/documenten/publicaties/202...
Personally I'm less concerned about the tank. It's obvious and easy to risk assess. I don't get why countries don't have any significant, and honestly out sized, response to hacking and spying.
The damage that is/can be done is outrageous.
Cyberattacks are much more analogous to traditional episonage than acts of war. States don't regard episonage as acts of war because it's something engaged in by all sides and which literally happens all the time, unlike tanks rolling across the border.
Politicians of course like to pretend otherwise ... I was reminded of this, shall we say, breath-taking question I saw Rep. Haley Stevens asking recently on cspan :)
https://www.c-span.org/video/?c5105488/user-clip-do-departme...
> So we shouldn't consider cyberattacks warfare? I mean, what are they doing over there? Do they have a department that is just focused on cyberattacks? 'Coz this is, sort of, in some respects, hard to wrap our heads around, right? I mean, we don't …
China Offers Full Support to Russia on Ukraine War https://www.newsweek.com/china-russia-ukraine-war-dong-jun-c...
China has actually supported Saudi Arabia's war on Yemen's Houthis more than they have supported Russia's war on Ukraine. When Saudi Arabia's F-15s started getting their wings blown off by by Iranian SAMs fired by Houthis it was Chinese drones that started hitting Houthi positions in Yemen.
For some reason there is little awareness about the close Saudi-China alliance here in the West.
"China's newly appointed defense chief and Shoigu discussed boosting military cooperation and coordination as the Russia-Ukraine war drags on. Tensions surrounding the Ukraine crisis have tested the resilience of the China-Russia partnership, with Beijing supporting the Kremlin's plans economically rather than openly amid international pressure."
> Eschew flamebait. Avoid generic tangents. Omit internet tropes.
> Please don't use Hacker News for political or ideological battle. That tramples curiosity.