I would think the real issue was wether they were closed enough in real world design to avoid a security issue through debug means.
It’s something they probably should allow developers to disable but it’s also being WILDLY overstated by clout seekers.
You can, from some angles, call this a security flaw or issue. Anyone calling it a backdoor - a term with a specific meaning intentional secret access - is being irresponsible imho
I think we both agree, this “vulnerability” is overstated.
The days of Metasploit 0-days are over, so now it's just loads of sensationalist reporting and box-ticking regulation in companies.
People in the real world report things - people on the internet read 3 out of 4 of the words in the headline and screech hysterically and run around spouting prophecies about the end of the world.
I am a person on the internet.
And espressif should have closed that gap without external pressure.
> "Tarlogic Security has detected a backdoor in the ESP32, a microcontroller that enables WiFi and Bluetooth connection and is present in millions of mass-market IoT devices
I'd like to believe the didn't have ulterior reasons to cry "backdoor" knowing that's not the case. That would be a huge indictment of the researchers' characters.
They wanted the spotlight and calling something a "backdoor in a chip used by a billion devices" does the job.
There is a possibility it did not cross their minds that those instructions could an issue.
In their blog post they were very open about what does commands do and it looks like some of their clients that do advanced things with their chips are also aware of the instructions.
Probably the idea that the company is Chinese was enough to not bother asking the manufacturer for documentation about the instructions.
What it doesn’t have is a backdoor.
The blog post is a "nothing to see here". You really fell for it? Do we still do car analogies? Here's this car with just a ignition button without keys, and keys to your home in the glovebox and the address already on the GPS... but the thief would have to break into the car first!
This analogy makes no sense at all. Once you break into a car, you can quite literally do anything to it. The keys to your home part is simply random.
If you can break into the application running on an ESP32, you already have full access to RAM etc. The debug HCI commands will not give you any extra access.
Yes, security researchers are incentivized to make issues seem like more of a problem than they are, and vendors are incentivized to minimize them. In this case, though, the reality is much closer to Espressif's version.
* as we assumed with sbcs like raspberypi earlier...