ZTE Backdoor
pastebin.com
pastebin.com
[1] https://www.networkworld.com/community/blog/cia-wants-spy-yo...
PS: http://www.forbes.com/sites/robertolsen/2011/02/24/huaweis-o...
Just don't.
I think this is a useful heuristic for deciding whether something should be legislated: "is this worth using violence over?"
Also, there is an interesting article on trusting hardware ( http://theinvisiblethings.blogspot.fr/2009/03/trusting-hardw... ) which was reposted two months ago on HN ( http://news.ycombinator.com/item?id=3656522 ).
"Open" in that they show you how they put together the black boxes. "Closed" because it's all made up of black boxes.
[1] http://wiki.openmoko.org/wiki/Neo_FreeRunner_Hardware#Hardwa...
[2] http://lists.openmoko.org/pipermail/community/2007-January/0...
Now if it was some daemon that set up a listening socket and linked to some APIs, ready to let an unidentified external party hook into the phonebook, or something like that, then I'd be screaming government, bloody government! :)
Your tinfoil hat might be defective.
Anyone who thinks the Chinese government had anything to do with this is just an idiot.
Free root form the manufacturer! Time to install another ROM.
People who care about this privacy issue usually don't use ZTE. No offense, but ZTE aims at the entry-level consumers, most of whom don't know what root is and only buy ZTE for the low price.
Besides, in China, there are way more to be worried than this non-issue. You know it...
If it's true, it would a great opportunity to see how Google/ZTE reacts to this vulnerability. How much time will ZTE take to correct this and issue an update? And also, will be able Google to stop applications who exploit this vulnerability to go public in the Market? I sincerely doubt it.
I highly doubt, considering the obvious nature and simplicity of the binary, that clandestine remote access (i.e. by the Chinese government or other such tinfoil hat theories) was the idea.
Especially given the name of the binary, I suspect some ZTE engineer was tasked with writing a desktop or mobile sync application that they decided needed root access for some reason. Said engineer then made a major mistake and decided a non-unique plaintext secret stored in the binary was adequate security. This happens all the time - see the recent RuggedCom "backdoor" fiasco [0]. It's happened at places I've worked, too, and it's not exactly new in the industry as a whole.
An engineer was uninformed or ignored security best practices and wrote code with a vulnerability. The vulnerability will be patched out. It's a big deal and it sucks (why were all setuid binaries not audited, at least to the level that basic oversights like this one would be noticed?), but at least in my mind it's not some kind of secret government control backdoor conspiracy - it's just a horrible bug.
[0]: http://www.nerc.com/fileUploads/File/Events%20Analysis/A-201...
Also, it's not a vulnerability either (from ZTE's point of view). It's a feature.