logoalt Hacker News

mike_hockyesterday at 2:01 PM2 repliesview on HN

A poorly documented or undocumented (debugging) backdoor in a chip marketed for ATMs and medical hardware, enabled by default, at the very least qualifies as reckless endangerment.


Replies

saidnooneevertoday at 3:39 AM

ofcourse. its just a difference between 'ooh china is evil' or 'derp some company has shit processes' which on a certain level is quite a big difference, though for most consumers will indeed boil down to the same.

sandworm101yesterday at 3:49 PM

Not really. A properly designed network should take account for such things as unknown/irreparable flaws. An irreparable backdoor in a device can be mitigated with a gatekeeper, something akin to a firewall that will not allow a threat actor to have access to a faulty device.

The real recklessness would be allowing an ATM unfettered access to the internet on the assumption that the manufacturer has already protected the device from every known and unknown threat.

show 2 replies