Hacker News new | ask | show | jobs
by thedingwing 2321 days ago
There was an article a few days ago about a software backdoor built by a different company that was unrelated to the actual silicon. Is this the same vulnerability, or is this one actually implemented in silicon?
1 comments

The link to the PoC is the same as for this submission: https://news.ycombinator.com/item?id=22251329

Same vulnerability. The reason HiSilicon couldn't provide the fix is that they didn't write the firmware running on those devices, Xiongmai did. This information was added as an update to the original writeup.

More interesting info on Xiongmai if anyone’s unfamiliar:

https://krebsonsecurity.com/2018/10/naming-shaming-web-pollu...