Hacker News new | ask | show | jobs
by srcmap 2548 days ago
From what I read, it sounds like Cisco put a file from public github into the IOT firmware's /root/.ssh directory.

Something is very wrong with that firmware generating process.

Why would anyone do that? Even accidentally?

1 comments

There is a nice talk on youtube (sorry, tried to find a link and couldn't in less than 30 seconds) that discusses Cisco's firmware build... "process". Rest assured, "very wrong" is a nice description; allegedly, we're talking things like "random engineer builds firmware image from local checkout using personal build scripts and uncommitted code, and if it appears to work then it gets shipped to customers, either at large or on a case-by-case basis". Honestly, the presence of additional random files is completely unsurprising.