Felix (FX) Lindner, a well known super hacker (for the white hats), has revealed at “Hack In The Box” that Huawei’s routers have so many security holes that using the hack he discovered (which requires physical connection) for the ‘static’ password is trivial. He won a cash prize for it.
"I don't know if there are backdoors - but it doesn't matter since there are so many vulnerabilities." – Felix Lindner
These were revealed by him at Defcon in July.
The really bad news? Huawei is the second largest Telcom in the world.
“This Monday Congress issued a report raising concerns about national security in relation to Huawei's suspected role in using technology to help the Chinese government expand its overseas spying operations.
The House Intelligence Committee released the findings Monday and has urged U.S. companies doing business with Huawei to use another vendor.”
The response from Huawei?
“William Plummer, Huawei vice president of external affairs, has warned of reprisals from foreign governments in response to the House panel’s conclusions. Blocking Huawei from doing business in the United States would set a "monstrous, market-distorting, trade-distorting policy precedent that could be used in other markets against American companies,” he has said.” - http://www.nextgov.com/cybersecurity/2012/10/chinas-defense-huawei-us-tech-companies-spy-too/58680/
Maybe the next ‘shortage’ will appear in U.S. equipment using Chinese manufactured parts (Cisco beware!).
On the upside, maybe outsourcing has finally showed its Achille’s heel.
It should have been “We’ll change our software security.”
“Needless to say, what Lindner has revealed at Hack In The Box today is a serious issue for all users of Huawei products.” - http://www.zdnet.com/hack-in-the-box-researcher-reveals-ease-of-huawei-router-access-7000005600/?s_cid=e539
Source:
http://www.zdnet.com/hack-in-the-box-researcher-reveals-ease-of-huawei-router-access-7000005600/?s_cid=e539
http://www.nextgov.com/cybersecurity/2012/10/chinas-defense-huawei-us-tech-companies-spy-too/58680/