06.27.13

Gemini version available ♊︎

Back Door Access Discovered in Backup Servers of HP, Showing Urgent Need to Dump Proprietary Software

Posted in Hardware, HP, Security at 9:30 am by Dr. Roy Schestowitz

Binary-only printer drivers can also be trusted no longer

HP printer

Summary: More revelations about back doors which go beyond ‘the cloud’ and into people’s desks or offices

HP has betrayed people’s trust, not just because it helps Microsoft suppress Free software adoption in the German government [1, 2] but also because its hardware has remotely-accessible back doors. Never again should you trust hardware from HP.

Not only Microsoft Skype is a horrific piece of spyware on people’s desk (with microphone and webcam). As it turns out, HP backup servers too have back doors. As one article put it, “StoreOnce backup systems are not low-end products: the version with twelve 1TB disks (with a usable capacity of 6TB) costs more than €12,000. The price premium compared to a normal server of this size is explained by the StoreOnce Catalyst software included with the server. According to HP, the product’s deduplication functionality reduces the size of data backups by up to 95 per cent.”

“These primarily US-based or Anglo-Saxon companies seem to have total disregard for privacy, as their spy agencies reveal”Towards the end it says: “The disclosure is given added spice by Technion’s decision to publish the SHA1 hash for the password for accessing the hidden administrator account. Hashes can be brute forced to obtain the actual password. It will not be long before the decrypted string is circulating on the usual forums. The password is just seven characters long and draws on a ten-year old meme.”

These primarily US-based or Anglo-Saxon companies seem to have total disregard for privacy, as their spy agencies reveal. It seems like Germany is finally taking note of this. A major German newspaper says: “Overzealous data collectors in the US and Great Britain have no right to investigate German citizens. The German government must protect people from unauthorized access by foreign intelligence agencies, and it must act now. This is a matter of national security.”

They should be dumping Windows in Germany, following Munich's lead. Christine Hall talks about back door access by the NSA into Windows when she writes:

Time to Take Advantage of Microsoft’s Vulnerabilities

[...]

It wasn’t news to most of us in the FOSS world that Microsoft was one of the companies shoveling information over to the NSA’s project PRISM. As much as we’d like, we can’t fault them any more than anyone else in that sordid affair. Only Yahoo comes out with any degree of redemption, since they at least bothered to go to court to try to stop the No-Such-Agency guys.

Nor were many of us surprised to discover Microsoft was making it easy for U.S. spooks to monitor traffic on Skype. That news probably damaged the folks in Redmond a little more than the plain vanilla NSA/PRISM story, but there was still some wiggle room for Ballmer. It started before Microsoft’s ownership. My people hardly knew what was going on. We’ll fix it. Yadda. Yadda. Yadda.

The latest news though, which so far seems to have little to do with the NSA scandal but plenty to do with espionage, might be a Windows breaker. Ballmer & Friends might not be able to squirm their way out of this, especially if the commercial GNU/Linux players get in gear and get moving.

This is definitely going to change how people view Windows. The latest TechBytes episode covers that as well. It’s reassuring to see what we covered for years becoming common knowledge, affecting people’s judgment. Free software is going to capitalise on all this.

Share in other sites/networks: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Reddit
  • email

Decor ᶃ Gemini Space

Below is a Web proxy. We recommend getting a Gemini client/browser.

Black/white/grey bullet button This post is also available in Gemini over at this address (requires a Gemini client/browser to open).

Decor ✐ Cross-references

Black/white/grey bullet button Pages that cross-reference this one, if any exist, are listed below or will be listed below over time.

Decor ▢ Respond and Discuss

Black/white/grey bullet button If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

DecorWhat Else is New


  1. [Meme] Germany's Licence to Break the Law

    Remember that the young Campinos asked dad for his immunity after he had gotten drunk and crashed the car; maybe the EPO should stop giving diplomatic immunity to people, seeing what criminals (e.g. Benoît Battistelli) this attracts; the German government is destroying its image (and the EU’s) by fostering such corruption, wrongly believing that it’s worth it because of Eurozone domination for patents/litigation



  2. EPO Dislikes Science and Scientists

    The EPO's management has become like a corrupt political party with blind faith in money and monopolies (or monopoly money); it has lost sight of its original goals and at this moment it serves to exacerbate an awful pandemic, as the video above explains



  3. Links 1/12/2021: LibreOffice 7.3 Beta, Krita 5.0, Julia 1.7

    Links for the day



  4. Links 1/12/2021: NixOS 21.11 Released

    Links for the day



  5. IRC Proceedings: Tuesday, November 30, 2021

    IRC logs for Tuesday, November 30, 2021



  6. Links 1/12/2021: Tux Paint 0.9.27 and WordPress 5.9 Beta

    Links for the day



  7. [Meme] EPO Administrative Council Believing EPO-Bribed 'Media' (IAM Still Shilling and Lying for Cash)

    IAM continues to do what brings money from EPO management and Team UPC, never mind if it is being disputed by the patent examiners themselves



  8. The EPO's Mythical “Gap” Has Been Found and It's Bonuses for People Who Use Pure Fiction to Steal From Patent Examiners

    The phony president who has the audacity to claim there's a budget gap is issuing millions of euros for his enablers to enjoy; weeks ahead of the next meeting of national delegates the Central Staff Committee (CSC) tells them: "Events show that the delegations’ concerns about functional allowances have materialised. The lack of transparency and inflation of the budget envelope gives rise to the suspicion that high management is pursuing a policy of self-service at the expense of EPO staff, which is difficult to reconcile with the Office’s claimed cost-saving policy, and to the detriment of the whole Organisation."



  9. Video: Making the Internet a Better Place for People, Not Megacorporations

    Following that earlier list of suggested improvements for a freedom-respecting Internet, here's a video and outline



  10. Links 30/11/2021: KDE Plasma 5.23.4, 4MLinux 38.0, Long GitHub Downtime, and Microsoft's CEO Selling Away Shares

    Links for the day



  11. A Concise Manifesto For Freedom-Respecting Internet

    An informal list of considerations to make when reshaping the Internet to better serve people, not a few corporations that are mostly military contractors subsidised by the American taxpayers



  12. Freenode.net Becomes a 'Reddit Clone' and Freenode IRC is Back to Old Configurations After Flushing Down Decades' Worth of User/Channel Data and Locking/Shutting Out Longtime Users

    Freenode is having another go; after “chits” and “jobs” (among many other ideas) have clearly failed, and following the change of daemon (resulting in massive loss of data and even security issues associated with impersonation) as well as pointless rebrand as “Joseon”, the domain Freenode.net becomes something completely different and the IRC network reopens to all



  13. Jack Dorsey's Decision is a Wake-up Call: Social Control Media is Just a Toxic Bubble

    The state of the World Wide Web (reliability, preservation, accessibility, compatibility etc.) was worsened a lot more than a decade ago; with social control media that’s nowadays just a pile of JavaScript programs we’re basically seeing the Web gradually turning into another Adobe Flash (but this time they tell us it’s a “standard”), exacerbating an already-oversized ‘bubble economy’ where companies operate at a loss while claiming to be worth hundreds of billions (USD) and generally serve imperialistic objectives by means of manipulation like surveillance, selective curation, and censorship



  14. IRC Proceedings: Monday, November 29, 2021

    IRC logs for Monday, November 29, 2021



  15. Links 29/11/2021: NuTyX 21.10.5 and CrossOver 21.1.0

    Links for the day



  16. This Apt Has Super Dumbass Powers. Linus Sebastian and Pop_OS!

    Guest post by Ryan, reprinted with permission



  17. [Meme] Trying to Appease Provocateurs and Borderline Trolls

    GNU/Linux isn’t just a clone of Microsoft Windows and it oughtn’t be a clone of Microsoft Windows, either; some people set themselves up for failure, maybe by intention



  18. Centralised Git Hosting Has a Business Model Which is Hostile Towards Developers' Interests (in Microsoft's Case, It's an Attack on Reciprocal Licensing and Persistent Manipulation)

    Spying, censoring, and abusing projects/developers/users are among the perks Microsoft found in GitHub; the E.E.E.-styled takeover is being misused for perception manipulation and even racism, so projects really need to take control of their hosting (outsourcing is risky and very expensive in the long run)



  19. Links 29/11/2021: FWUPD's 'Best Known Configuration' and Glimpse at OpenZFS 3.0

    Links for the day



  20. President Biden Wants to Put Microsofter in Charge of the Patent Office, Soon to Penalise Patent Applicants Who Don't Use Microsoft's Proprietary Formats

    The tradition of GAFAM or GIAFAM inside the USPTO carries on (e.g. Kappos and Lee; Kappos lobbies for Microsoft and IBM, whereas Lee now works for Amazon/Bezos after a career at Google); it's hard to believe anymore that the USPTO exists to serve innovators rather than aggressive monopolists, shielding their territory by patent threats (lawsuits or worse aggression) and cross-licensing that's akin to a cartel



  21. Microsoft GitHub Exposé — Part VIII — Mr. Graveley's Long Career Serving Microsoft's Agenda (Before Hiring by Microsoft to Work on GitHub's GPL Violations Machine)

    Balabhadra (Alex) Graveley was promoting .NET (or Mono) since his young days; his current job at Microsoft is consistent with past harms to GNU/Linux, basically pushing undesirable (except to Microsoft) things to GNU/Linux users; Tomboy used to be the main reason for distro ISOs to include Mono



  22. Dr. Andy Farnell on Teaching Cybersecurity in an Age of 'Fake Security'

    By Dr. Andy Farnell



  23. IRC Proceedings: Sunday, November 28, 2021

    IRC logs for Sunday, November 28, 2021



  24. Links 29/11/2021: Linux 5.16 RC3 and Lots of Patent Catch-up

    Links for the day



  25. By 2022 0% of 'News' Coverage About Patents Will Be Actual Journalism (Patent Litigation Sector Has Hijacked the World Wide Web to Disseminate Self-Promotional Misinformation)

    Finding news about the EPO is almost impossible because today’s so-called ‘news’ sites are in the pockets of Benoît Battistelli, António Campinos, and their cohorts who turned the EPO into a hub of litigation, not science; this is part of an international (worldwide) problem because financial resources for journalism have run out, and so the vacuum is filled/replaced almost entirely by Public Relations (PR) and marketing



  26. Trying to Appease Those Who Never Liked Free Software or Those Who Blindly Loved All Patent Monopolies to Begin With

    It’s crystal clear that trying to appease everyone, all the time, is impossible; in the case of the EPO, for example, we hope that exposing Team Battistelli/Campinos helps raise awareness of the harms of patent maximalism, and when speaking about Free software — whilst occasionally bashing the alternatives (proprietary) — we hope to convince more people to join the “Good Fight”



  27. Links 28/11/2021: Laravel 8.73 Released, GitHub Offline for Hours

    Links for the day



  28. IRC Proceedings: Saturday, November 27, 2021

    IRC logs for Saturday, November 27, 2021



  29. Links 27/11/2021: Nvidia’s DLSS Hype and Why GNU/Linux Matters

    Links for the day



  30. [Meme] Linus Gabriel Sebastian Takes GNU/Linux for a (Tail)'Spin'

    If you’re trying to prove that GNU/Linux is NOT Windows, then “haha! Well done…”


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts