From China, With Love
devttys0.com
devttys0.com
Without examination, existing circumstances repeatedly demonstrate that we more than a bit likely to be subjected to hidden weaknesses and exploitations we are uninformed about and have not agreed to.
----
(1) decompilation/reversing, as in the referenced, recent D-Link case, or perhaps even simple extraction of a compressed fileset
I also seem to recall ongoing efforts to (further) criminalize various forms of infringement (as opposed to leaving them matters of civil law), taking accusations to a whole new level of hurt.
http://www.law.cornell.edu/uscode/text/17/1201
I am no law scholar, but I get the impression that, in general, reverse engineering and research are exempt from most forms of IP protection (which is what the DMCA is).
* How much do we know about Shenzhen Tenda? All I could find in 5 minutes or so of research is that it's the result of the efforts of D.P. Quan to provide networking and enrich the lives of all people through, IIRC, excellence.
* China has a very well-established, well-attributed track record of attacking the tech infrastructure of the rest of the world, and does so through proxy organizations.
* A very blatant backdoor with minimal tech support value is something that is more valuable to a state than to a random tech company.
Chinese gadgets have backdoor - evil Communist country making a grand scheme.
mh, so not really phoning home is it ? I thought this was pretty interesting until i read that..thats a pretty minimal security risk.
Anyone with a "whole network" who remotely knows what hes doing wont be using a router like that one.
Which router would he use?
If you can dream up a sick way to mess with people, odds are there is a government somewhere funding research into it.
I'd say routers are particularly vulnerable, if only because they are smart (Linux) machines, but in most cases users will never check them for anything odd going on. As this article shows, it takes but a simple command for them to execute stuff, and given how Linux is a general purpose OS, they could install and perform any kind of task - like install backdoors and whatnot on the PC's behind the routers, which can then in turn be disabled or used in a massive botnet to perform a DDoS or other attacks on other systems.
Just think about the implications of there being a backdoor in every internet-connected computer system, or the consequences of all-out cyberwar.
One of my Projects attempts to solve this problem for the new generation of IP-enabled Appliances/Devices. I plan to make the process painless and easy. Everyone wins, both customer/consumer and developers/providers. Does anyone want to build it with me?
[1] http://www.washingtonpost.com/blogs/the-switch/wp/2013/10/14...
Disassemblers are a good target for open source development. They're commercially valuable only for a very small subset of users, and the market leader is terribly mispriced relative to the value it provides, which drags the whole commercial market for them down.
https://www.hex-rays.com/products/ida/support/download_freew...
[0] - https://openwrt.org/
As an example of the latter, I have a Monoprice-rebadged Tenda W301A ceiling-/wall-mount AP on my desk. It only has 2 MB of flash and 16 MB of RAM. It has a TTL serial port, but the lines are broken out to surface pads that aren't even grouped together on the PCB. (They're not labelled on the silkscreen, either.) The version of u-boot it ships with is stripped down to nothing, probably because of the limited flash space available. For ≤$5 more on the BOM, these problems could be fixed, and the device would be considerably more useful.
If it's China you are worried about, perhaps work with a domestic chip producer like Broadcom. The chips might be fabbed in China, but it would be pretty difficult for China to sneak a "phone home" module into a GDSII drop.
As an Engineer, I find the project completely fascinating. I believe that this project will (or already has) enhance Infrastructure/Datacenter Design and pave the way for the next generation of Software Defined Networking (SDN) Solutions. In some ways, the Open Compute Project is sort of flying under the radar. When you say Facebook to someone, they probably think of the Product. But if you take a look at what they're doing with this Project, and how it can impact underlying infrastructure, this is amazing. There are other things they're working on (not directly networking related) that are also amazing. Another project I find fascinating is the Prism Project (no, not the NSA one, the Facebook one). Right in line with Google's Spanner. Pretty cool stuff!
userRpmNatDebugRpm26525557