Skip to content

Comment on Energizer battery charger contains backdoorparent

Comments

Remember that article we had here on HN a few weeks back about Chinese spies infiltrating companies to get company information? It is improbable, but a similar thing could have easily been done with this. All they would have to do is get their own code substituted into the production process and they get an instant backdoor into many, many computers.

A more likely scenario, though, is that a tech savvy and angry employee wanted to get back at the company that was about to fire him. Imagine if a DDOS was launched against Energizer using code distributed by one of their own products. Ultimate irony!

I'm not saying either of these theories are legitimate, or even probable, but who knows?

I bought a cheap router about 8 years ago that sent all of my DNS requests through some IP address in China.

Which raises an interesting question. How many people here monitor the link between their router and their cable modem? I certainly don't.

I use DD-WRT, so anything malicious from the router provider would have to be in hardware.

Good thing hardware doesn't rely on running complicated firmware... :)

DD-WRT is the firmware for the most part although I'd bet there's some embedded code running below this Linux-based OS. Is there enough wiggle room "down there" to, say, surreptitiously forward inbound traffic between network segments and back (like a mini NAT)? I have no idea. Does anyone here know anything about the WRT54GL board?

The DD-WRT is just general purpose computer operating system that happens to be configured as a router which Linksys calls firmware to discourage you from tinkering with it. The ethernet and wireless devices, though, have more code, several thousands lines of it, running on slower, low power (but still complex) processors.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.