The backdoor on Contec CMS8000 patient-monitoring devices could allow an IP address at an unnamed university to remotely download and execute unverified files, according to CISA.

  • sunzu2
    link
    fedilink
    -31 day ago

    everything has a backdoor… can we quit pretending that these zero day CVE are not back doors?

    or we can’t start naming them unless it is Chinese doing it?

    • @[email protected]
      link
      fedilink
      English
      20
      edit-2
      1 day ago

      Knock it off with the propaganda.

      This is literally a deliberate back door.

      And no, we can’t call zero days backdoors because they are not same thing.

      The equipment, from China-based Contec Medical Systems, was mysteriously configured to connect to an IP address for a third-party university with no connection to the manufacturer.

      The backdoor enables the IP address at the unnamed university to remotely download and execute unverified files on the patient monitor, CISA’s report says. In addition, the same backdoor automatically sends patient data to the IP address.

      • @[email protected]
        link
        fedilink
        English
        -41 day ago

        There are valid questions, many of which revolve around how and why it’s used.

        Some systems have brain damaged approaches to diagnostics/logging, license enforcement, or remote service/update systems that create security holes but are not intentionally malicious.

        Security is hard and we should remember Hanlon’s Razor.

        • @Benjaben
          link
          English
          61 day ago

          I get lots of mileage out of Hanlon’s Razor, and I acknowledge the rampant incompetence that suggests its applicability, but digital security seems like about the least appropriate place to apply this rule of thumb.

          • @[email protected]
            link
            fedilink
            English
            51 day ago

            As someone who has to deal with PCI compliance issues, there’s plenty of noob mistakes, out-of-date thinking and outright “let’s log this data for debugging purposes even though if any regulator found out they’d nuke us from orbit.”

            • @Benjaben
              link
              English
              31 day ago

              Fair enough, I can imagine that pretty easily.

      • sunzu2
        link
        fedilink
        -51 day ago

        Knock it off with the propaganda.

        Please clarify this statement.

          • sunzu2
            link
            fedilink
            27 hours ago

            People protested the chinaman regime, some people got killed but not on the actual square tho?

            There is a famous picture of a man protesting in front of a tank.

            If you think I am a tankie, just check my body of work on here lol

            Y’all cant see past these basic concepts… Much more work to be done.