Hacker News new | ask | show | jobs
by grammarxcore 2330 days ago
I misinterpreted the title. Fortinet has removed backdoors from SSH and databases in its product. Granted, I'm genuinely surprised any security program has this feature:

> "FortiSIEM has a hardcoded SSH public key for user 'tunneluser' which is the same between all installs," said Andrew Klaus, the security researcher who identified this issue.

What other horrible assumptions have been hardcoded into this product that we have yet to discover?