06.27.13

Gemini version available ♊︎

Back Door Access Discovered in Backup Servers of HP, Showing Urgent Need to Dump Proprietary Software

Posted in Hardware, HP, Security at 9:30 am by Dr. Roy Schestowitz

Binary-only printer drivers can also be trusted no longer

HP printer

Summary: More revelations about back doors which go beyond ‘the cloud’ and into people’s desks or offices

HP has betrayed people’s trust, not just because it helps Microsoft suppress Free software adoption in the German government [1, 2] but also because its hardware has remotely-accessible back doors. Never again should you trust hardware from HP.

Not only Microsoft Skype is a horrific piece of spyware on people’s desk (with microphone and webcam). As it turns out, HP backup servers too have back doors. As one article put it, “StoreOnce backup systems are not low-end products: the version with twelve 1TB disks (with a usable capacity of 6TB) costs more than €12,000. The price premium compared to a normal server of this size is explained by the StoreOnce Catalyst software included with the server. According to HP, the product’s deduplication functionality reduces the size of data backups by up to 95 per cent.”

“These primarily US-based or Anglo-Saxon companies seem to have total disregard for privacy, as their spy agencies reveal”Towards the end it says: “The disclosure is given added spice by Technion’s decision to publish the SHA1 hash for the password for accessing the hidden administrator account. Hashes can be brute forced to obtain the actual password. It will not be long before the decrypted string is circulating on the usual forums. The password is just seven characters long and draws on a ten-year old meme.”

These primarily US-based or Anglo-Saxon companies seem to have total disregard for privacy, as their spy agencies reveal. It seems like Germany is finally taking note of this. A major German newspaper says: “Overzealous data collectors in the US and Great Britain have no right to investigate German citizens. The German government must protect people from unauthorized access by foreign intelligence agencies, and it must act now. This is a matter of national security.”

They should be dumping Windows in Germany, following Munich's lead. Christine Hall talks about back door access by the NSA into Windows when she writes:

Time to Take Advantage of Microsoft’s Vulnerabilities

[...]

It wasn’t news to most of us in the FOSS world that Microsoft was one of the companies shoveling information over to the NSA’s project PRISM. As much as we’d like, we can’t fault them any more than anyone else in that sordid affair. Only Yahoo comes out with any degree of redemption, since they at least bothered to go to court to try to stop the No-Such-Agency guys.

Nor were many of us surprised to discover Microsoft was making it easy for U.S. spooks to monitor traffic on Skype. That news probably damaged the folks in Redmond a little more than the plain vanilla NSA/PRISM story, but there was still some wiggle room for Ballmer. It started before Microsoft’s ownership. My people hardly knew what was going on. We’ll fix it. Yadda. Yadda. Yadda.

The latest news though, which so far seems to have little to do with the NSA scandal but plenty to do with espionage, might be a Windows breaker. Ballmer & Friends might not be able to squirm their way out of this, especially if the commercial GNU/Linux players get in gear and get moving.

This is definitely going to change how people view Windows. The latest TechBytes episode covers that as well. It’s reassuring to see what we covered for years becoming common knowledge, affecting people’s judgment. Free software is going to capitalise on all this.

Share in other sites/networks: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Reddit
  • email

Decor ᶃ Gemini Space

Below is a Web proxy. We recommend getting a Gemini client/browser.

Black/white/grey bullet button This post is also available in Gemini over at this address (requires a Gemini client/browser to open).

Decor ✐ Cross-references

Black/white/grey bullet button Pages that cross-reference this one, if any exist, are listed below or will be listed below over time.

Decor ▢ Respond and Discuss

Black/white/grey bullet button If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

DecorWhat Else is New


  1. Dotcom Boom and Bust, Round 2

    The age of technology giants/monopolies devouring everything or military-funded (i.e. taxpayers-subsidised) surveillance/censorship tentacles, in effect privatised eyes of the state, may be ending; the United States can barely sustain that anymore and raising the debt ceiling won't solve that (buying time isn't the solution)



  2. Society Would Benefit From a Smartphoneshame Movement

    In a society plagued by blackmail, surveillance and frivolous lawsuits it is important to reconsider the notion of “smart” phone ownership; these devices give potentially authoritarian companies and governments far too much power over people (in the EU they want to introduce new legislation that would, in effect, ban Free software if it enables true privacy)



  3. IRC Proceedings: Friday, February 03, 2023

    IRC logs for Friday, February 03, 2023



  4. IRC Proceedings: Thursday, February 02, 2023

    IRC logs for Thursday, February 02, 2023



  5. Links 03/02/2023: Proton 7.0-6 Released, ScummVM 2.7 Testing

    Links for the day



  6. Links 03/02/2023: OpenSSH 9.2 and OBS Studio 29.0.1

    Links for the day



  7. Links 03/02/2023: GNU C Library 2.37

    Links for the day



  8. Sirius Finished

    Yesterday I was sent a letter approving my resignation from Sirius ‘Open Source’, two months after I had already announced that I was resigning with immediate effect; they sent an identical letter to my wife (this time, unlike before, they remembered to also change the names!!)



  9. The Collapse of Sirius in a Nutshell: How to Identify the Symptoms and Decide When to Leave

    Sirius is finished, but it's important to share the lessons learned with other people; there might be other "pretenders" out there and they need to be abandoned



  10. Links 03/02/2023: WINE 8.1 and RapidDisk 9.0.0

    Links for the day



  11. Links 02/02/2023: KDE Gear 22.12.2 and LibreOffice 7.5

    Links for the day



  12. Linux News or Marketing Platform?

    Ads everywhere: Phoronix puts them at the top, bottom, navigation bar, left, and right just to read some Microsoft junk (puff pieces about something that nobody other than Microsoft even uses); in addition there are pop-ups asking for consent to send visitors’ data to hundreds of data brokers



  13. Daily Links at Techrights Turn 15, Time to Give Them an Upgrade

    This year we have several 15-year anniversaries; one of them is Daily Links (it turned 15 earlier this week) and we've been working to improve these batches of links, making them a lot more extensive and somewhat better structured/clustered



  14. Back to Focusing on Unified Patent Court (UPC) Crimes and Illegal Patent Agenda, Including the EPO's

    The EPO's (European Patent Office, Europe's second-largest institution) violations of constitutions, laws and so on merit more coverage, seeing that what's left of the "media" not only fails to cover scandalous things but is actively cheering for criminals (in exchange for money)



  15. European Patent Office Staff Votes in Favour of Freedom of Association (97% of Voters in Support)

    The Central Staff Committee (CSC) at the EPO makes a strong case for António Campinos to stop breaking and law and actually start obeying court orders (he’s no better than Benoît Battistelli and he uses worse language already)



  16. Links 02/02/2023: Glibc 2.37 and Go 1.20

    Links for the day



  17. IRC Proceedings: Wednesday, February 01, 2023

    IRC logs for Wednesday, February 01, 2023



  18. Links 01/02/2023: Security Problems, Unrest, and More

    Links for the day



  19. Links 01/02/2023: Stables Kernels and Upcoming COSMIC From System76

    Links for the day



  20. IRC Proceedings: Tuesday, January 31, 2023

    IRC logs for Tuesday, January 31, 2023



  21. Links 31/01/2023: Catchup Again, Wayland in Xfce 4.20

    Links for the day



  22. Links 31/01/2023: elementary OS 7

    Links for the day



  23. Intimidation Against Nitrux Development Team Upsets the Community and Makes the Media Less Trustworthy

    Nitrux is being criticised for being “very unappealing”; but a look behind the scenes reveals an angry reviewer (habitual mouthpiece of the Linux Foundation and Linux foes) trying to intimidate Nitrux developers, who are unpaid volunteers rather than “corporate” developers



  24. Links 31/01/2023: GNOME 44 Wallpapers and Alpha

    Links for the day



  25. Free and Open Source Software Developers' European Meeting (FOSDEM) and KU Leuven Boosting Americans and Cancellers of the Father of Free Software

    The Free Software Foundation (FSF) and its founder, Richard M. Stallman (RMS), along with the SFLC one might add, have been under a siege by the trademark-abusing FSFE and SFC; Belgium helps legitimise the ‘fakes’



  26. Techrights in the Next 5 or 10 Years

    Now that I’m free from the shackles of a company (it deteriorated a lot after grabbing Gates Foundation money under an NDA) the site Techrights can flourish and become more active



  27. 60 Days of Articles About Sirius 'Open Source' and the Long Road Ahead

    The Sirius ‘Open Source’ series ended after 60 days (parts published every day except the day my SSD died completely and very suddenly); the video above explains what’s to come and what lessons can be learned from the 21-year collective experience (my wife and I; work periods combined) in a company that still claims, in vain, to be “Open Source”



  28. IRC Proceedings: Monday, January 30, 2023

    IRC logs for Monday, January 30, 2023



  29. Taking Techrights to the Next Level in 2023

    I've reached a state of "closure" when it comes to my employer (almost 12 years for me, 9+ years for my wife); expect Techrights to become more active than ever before and belatedly publish important articles, based on longstanding investigations that take a lot of effort



  30. The ISO Delusion: When the Employer Doesn’t Realise That Outsourcing Clients' Passwords to LassPass After Security Breaches Is a Terrible Idea

    The mentality or the general mindset at Sirius ‘Open Source’ was not compatible with that of security conscientiousness and it seemed abundantly clear that paper mills (e.g. ISO certification) cannot compensate for that


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts