Hacker News new | ask | show | jobs
by lstamour 3869 days ago
I'm not sure I'd trust Arris products at this point. From another blog post in 2014: "It is worth noting that on previous FW revisions the CGI calls did NOT require any authentication and could be called without providing a valid "credential" cookie." http://console-cowboys.blogspot.ca/2014/09/arris-cable-modem...

With mistakes like that, and three layers of backdoors, I'm half expecting discoveries of hardware backdoors next ...