top | item 37571011

(no title)

tekeous | 2 years ago

I wonder if MikroTik would be compromised- they’re Latvian and don’t necessarily have to bow to the NSA.

discuss

order

HideousKojima|2 years ago

I assume by default that any hardware from any NATO nation is compromised by the NSA and other Western intelligence agencies. I also assume that any Chinese or Russian hardware is compromised by their respective intelligence agencies. And I assume that the NSA and other Western agencies are constantly trying to get backdoors into Chinese hardware (and I assume the Chinese are trying the do the same to ours). You're basically screwed no matter what.

ok123456|2 years ago

Buy products that are compromised by both, and let them battle it out. Sort of like the inverse of the plot of the movie hackers.

pizzalife|2 years ago

There's been plenty of remote 0days in MikroTik's products. At one point people were paying a pretty penny for them.

somehnguy|2 years ago

I think it’s worth noting that these vulnerabilities affected devices which had their management page open to the internet, which is universally known as a bad idea. At least the ones I’ve seen.

There is a big difference between an exploit affecting all devices vs a subset which requires a specific not-best-practice configuration. Regardless, still good to be aware they exist.

chinathrow|2 years ago

> have to bow to the NSA

You don't have to bow in order to be compromised. You can be compromised without even knowing it.

ElectricalUnion|2 years ago

Several MikroTik routers use marvel hardware underneath. So marvel might be compelled to backdoor the hardware for the NSA.

some_random|2 years ago

Why would the NSA need to strong arm MikroTik to implement a backdoor when they can pay ~10k for an 0-day to do the exact same thing?

irreticent|2 years ago

Because zero day vulnerabilities are usually patched when discovered by the vendor. They're completely different than an intentional backdoor.

paganel|2 years ago

> they’re Latvian and don’t necessarily have to bow to the NSA. reply

The majority (I'd say all) of the Eastern-European countries that are also NATO members do in fact bow to the US, and thus to the NSA/FBI/the Secret Service.

smolder|2 years ago

MikroTik has come up in their slides before, yes...

greenie_beans|2 years ago

i've always assumed they were the least secure of all my networking hardware

greenie_beans|2 years ago

ah shit now i've outed myself to the fbi if they didn't already know this about my network