" … with customer provided access and permission can allow HP support … "
Which, cynically, could easily be read as "with the storage device on a network, and with a company policy requiring support staff to request permission before using it".
Maybe these things aren't _intended_ to be directly internet connected - but there's a _lot_ of gear that ebds up that way without ever having been designed too. Even HP admit: "This vulnerability could be remotely exploited to gain unauthorized access to the device."
And from the end of the article - it seems at most: "And, of course, there's the "reset factory defaults" option, which would nuke all a user's data." - still not a "backdoor", but somewhat worse than just "a reboot".
Comments
" … with customer provided access and permission can allow HP support … "
Which, cynically, could easily be read as "with the storage device on a network, and with a company policy requiring support staff to request permission before using it".
Maybe these things aren't _intended_ to be directly internet connected - but there's a _lot_ of gear that ebds up that way without ever having been designed too. Even HP admit: "This vulnerability could be remotely exploited to gain unauthorized access to the device."
And from the end of the article - it seems at most: "And, of course, there's the "reset factory defaults" option, which would nuke all a user's data." - still not a "backdoor", but somewhat worse than just "a reboot".