So far, all of Huawei’s found potential backdoors turned out to be them being extremely terrible at writing secure software or developing secure operating procedures.
That’s how you write a backdoor in 2023 “oops… Guess I made a mistake again”
That was always the defence, but by that standard every piece of software is full of bugs. Microsoft Windows? Gets ten to twenty backdoors closed every month! Linux? Backdoors are closed weekly! WordPress plugins? Those are just backdoors that come with a theme!
No Cisco-style obfuscated, hard-coded admin password has ever been found in Huawei stuff. Their firmware was behind on security patches for open source software and I believe they did some firmware updates over HTTP, but in that area they’re not much worse than any of their competitors. When Vodafone did a vulnerability assessment of their network, which then got leaked, Bloomberg called telnet (within an air-gapped network) a “backdoor”, but Vodafone itself denies that. The biggest issue I remember Vodafone finding was the fact that Huawei tried to get remote management on the devices they installed so they didn’t need to be sent out to the field every time they needed to do maintenance; not uncommon for network vendors, but obviously not acceptable within carrier networks with locked-down security controls.
If there are real backdoors, then Huawei is just better at hiding them than their western counterparts. All we have to go on right now is secret documents from government agencies that pinky-swear that they really found backdoors that no independent researcher has been able to verify. There are a lot of wild stories about Huawei backdoors on the internet, but I have yet to see proof of any of a real backdoor.
That’s how you write a backdoor in 2023 “oops… Guess I made a mistake again”
That was always the defence, but by that standard every piece of software is full of bugs. Microsoft Windows? Gets ten to twenty backdoors closed every month! Linux? Backdoors are closed weekly! WordPress plugins? Those are just backdoors that come with a theme!
No Cisco-style obfuscated, hard-coded admin password has ever been found in Huawei stuff. Their firmware was behind on security patches for open source software and I believe they did some firmware updates over HTTP, but in that area they’re not much worse than any of their competitors. When Vodafone did a vulnerability assessment of their network, which then got leaked, Bloomberg called telnet (within an air-gapped network) a “backdoor”, but Vodafone itself denies that. The biggest issue I remember Vodafone finding was the fact that Huawei tried to get remote management on the devices they installed so they didn’t need to be sent out to the field every time they needed to do maintenance; not uncommon for network vendors, but obviously not acceptable within carrier networks with locked-down security controls.
If there are real backdoors, then Huawei is just better at hiding them than their western counterparts. All we have to go on right now is secret documents from government agencies that pinky-swear that they really found backdoors that no independent researcher has been able to verify. There are a lot of wild stories about Huawei backdoors on the internet, but I have yet to see proof of any of a real backdoor.
What you want to look for is a pattern of similar bugs that result in the same end result, e.g. https://t.me/durov/196
It can also just be bad programmers but that’s kind of the point … plausible deniability