[ExI] Three different surveillance firmware implants were made in in Chinese routers sold worldwide

Adrian Tymes atymes at gmail.com
Mon Aug 31 16:39:32 UTC 2026


On Mon, Aug 31, 2026 at 6:14 AM Ben Zaiboc via extropy-chat
<extropy-chat at lists.extropy.org> wrote:
> On 31/08/2026 03:22, Adrian Tymes wrote:
> > On Sun, Aug 30, 2026 at 10:05 AM Ben Zaiboc via extropy-chat
> > <extropy-chat at lists.extropy.org> wrote:
> >> On 29/08/2026 21:11, John K Clark wrote:
> >>> "These aren't conventional vulnerabilities where someone accidentally forgot to bounds-check a buffer. These are pieces of software deliberately included in the router firmware that provide remote access to the device. We would normally call this malware"
> >> I don't understand the 'normally' bit.
> >>
> >> This /is/ malware. We should be calling it malware. Why would anyone not call it malware?
> > Because of the technicality that it's working as intended by the maker
> > of the system, rather than being added by a third party.
>
> Hmm, that's falling into the trap of assuming that the proper function of a thing is what the maker intends, and not what the user intends.

Agreed, but that trap is in the generally accepted definition of
"malware".  I did say it was a technicality - and you were asking
about "anyone", which means the explanation is from their point of
view, including the definitions they use no matter whether you agree
with them or not.



More information about the extropy-chat mailing list