[ExI] Three different surveillance firmware implants were made in in Chinese routers sold worldwide

Ben Zaiboc benzaiboc at proton.me
Mon Aug 31 10:13:33 UTC 2026


On 31/08/2026 03:22, Adrian Tymes wrote:
> On Sun, Aug 30, 2026 at 10:05 AM Ben Zaiboc via extropy-chat
> <extropy-chat at lists.extropy.org> wrote:
>> On 29/08/2026 21:11, John K Clark wrote:
>>> "These aren't conventional vulnerabilities where someone accidentally forgot to bounds-check a buffer. These are pieces of software deliberately included in the router firmware that provide remote access to the device. We would normally call this malware"
>> I don't understand the 'normally' bit.
>>
>> This /is/ malware. We should be calling it malware. Why would anyone not call it malware?
> Because of the technicality that it's working as intended by the maker
> of the system, rather than being added by a third party.


Hmm, that's falling into the trap of assuming that the proper function of a thing is what the maker intends, and not what the user intends.

Routers exist because people want to use them, not because manufacturers want to make them. I know it's popular and encouraged to view things the other way round (thanks to the likes of Apple, Amazon, Google, Microsoft, etc.), and remove all the power from the user, but without consumers, nothing would get made. If you buy something, and it doesn't do what you want, you don't regard yourself as the one at fault (unless you bought the wrong thing in the first place). We even have a legal concept of 'fitness for purpose'. These routers covertly do things that their users don't want, so they are malware.

-- 
Ben



More information about the extropy-chat mailing list