The Register Home Page

back to article Iran claims US used backdoors to knock out networking equipment during war

Iranian media is claiming that the US used backdoors and/or botnets to disable networking equipment during the current war, and Chinese state media is dining out on the allegations. Reports from Iran claim hardware made by Cisco, Juniper, Fortinet, and MikroTik either rebooted or disconnected during recent attacks on Iran – …

Page:

    1. Claptrap314 Silver badge

      Re: Policy Change - in the Wrong Direction

      There are many reasons to play strong or even strongest "cards" when a lesser one might win a particular engagement.

      We certainly did not need to nuke Japan in order to win. We just didn't want to lose a million of ours + three million of theirs to do it. We also wanted to make it clear to the Soviets that we had & were willing to make use of the weapons.

      In the case of cyber exploits, however, a major one is that vulnerabilities don't age very well. It's not "user or lose" like in a missile exchange, but EVERY SINGLE report of a RAT happens when they get discovered. When that happens, not just the discoverer, but most (hopefully all, but I'm not stupid) users then update their systems to close the back door.

      Another way to put it is, "Who said that the back doors we used were the latest/greatest/best?"

      1. Sproggit Silver badge

        Re: Policy Change - in the Wrong Direction

        Two quick observations on your points.

        First, there is plenty of evidence - if not overwhelming evidence - that the US had cracked Japanese Navy ciphers and had decided the message that informed the fleet of Japan's intent to surrender *before* Enola Gay dropped "Little Boy" on Hiroshima, on August 6th, 1945. I don't think that undermines the spirit of your argument - that sometimes you need to "make a move" that also "makes a statement" .. but I don't think I can agree with anyone who says that it was right to "make a statement" that resulted in the deaths of between 80,000-140,000 people, most of whom were civilians.

        Second, I may have failed to articulate my point clearly. In your reply you suggest that many vulnerabilities may be of the "use them or lose them" variety and this is why it made sense for the US to exploit those back doors before they were discovered and patched. I think there's something of an argument that we might be able to make in that regard... if the target had access to new technology and the budget to keep their tech and vulnerability patching up to date. But my point was much more "ATT&CK" than "CAPEC" - namely that the risk to the US was as much about "sources and methods" (Tactics and Techniques) as it was about specific vulnerabilities.

        For example, think about SPECTRE and Meltdown, the two high-profile speculative execution vulnerabilities that were found in Intel chips a little while back. As soon as news of those flaws became public, other researchers found similar vulnerabilities in other silicon. It wasn't knowing that SPECTRE existed on Intel chips that was the big deal, it was knowing how it was found, what to look for, how to scan an environment to find similar examples and so on.

        China, Russia and others are going to be able to "work backwards from the point of impact" and learn a great deal about US techniques. They may find forensic evidence left behind. They may find new ways to scan for the exploited vulnerabilities - once they know what they are and devise test to detect them for themselves.

        But most importantly of all... the last thing you want to be doing with your cyber offense capability is a "shock and awe" campaign. Not when you don't know who else is watching or what they will see.

        1. Claptrap314 Silver badge

          Re: Policy Change - in the Wrong Direction

          Wow. That's quite a load you've got there.

          1) There were not 80000 -140000 Japanese deaths caused by the bombs, unless you only count the immediately killed. A more realistic number is 400000.

          2) US war planners estimate 1000000 US soldiers, 1000000 Japanese soldiers, and 2000000 Japanese civilian casualties in the event of an invasion. The Japanese exhibited astounding martial spirit, which these numbers reflect.

          3) Even AFTER the second nuclear bomb, the Japanese cabinet voted to continue fighting. The Emperor intervened to bring about the surrender.

          4) Given the above, it is deeply insulting to suggest that the Japanese navy would consider surrender without being ordered to do so.

          5) As documented in David Khan's The Codebreakers, written in 1970, the US had the ability to read essentially all Japanese communications during the entire war. There is no "evidence" to trumpet 50 years after the fact.

          6) As for ATT&CK, feel free to pontificate as to how the game is played at that level. But what we've seen from the Spanish Civil war through the Russian invasion of Ukraine, second- and third-tier conflicts have historically been testing grounds for new systems by the major powers. We appear to agree that cyber warfare is fundamentally of a different character than what has come before. I don't agree that you or I have ANYWHERE near the amount of level of data to make sound judgements about the impacts of the use of such weapons.

          7) I never intended to suggest that cyberweapons are good for shock & awe. I was merely pointing out that war ain't contract bridge.

    2. Anonymous Coward
      Anonymous Coward

      Re: Policy Change - in the Wrong Direction

      China doesn't need to be grateful. They already know everything about US cyber-offensive capabilities because all that stuff is made in China.

      1. Sproggit Silver badge

        Re: Policy Change - in the Wrong Direction

        When you use the term "made" you may be implying hardware... But of course that is not true with software. And it is in software that vulnerabilities and exploits are most common [that's inherent to the "nature of the beast" - hardware is rarely as complex as software - with the possible exception of microprocessors, some microcontrollers and VLSI chips.

        We don't know the details of the cyber strikes or what specifically was attacked.

        But my hunch is that it will be software vulnerabilities that were exploited. Not an absolute certainty - Stuxnet is proof of that.

        But on a balance of probabilities, this was a software-based attack.

  1. Fruit and Nutcase Silver badge
    Black Helicopters

    Buy American to ensure no Chinese backdoors

    Buy Chinese to ensure no American backdoors

    1. retiredFool Silver badge

      Buy Euro

      to ensure neither US or China back doors. Come on EU, make some enterprise routers.

      1. Claptrap314 Silver badge
        Trollface

        Re: Buy Euro

        With their components designed in the US & manufactured in China....

        1. Paul Crawford Silver badge

          Re: Buy Euro

          Hopefully not the software...

          1. Excused Boots Silver badge

            Re: Buy Euro

            Yes but if the hardware/firmware is pre-compromised, then.....

          2. Fruit and Nutcase Silver badge
            Mushroom

            Re: Buy Euro

            ...it'll be offshored to India

        2. Anonymous Coward
          Anonymous Coward

          Re: Buy Euro

          ... and Ethernet done in Israel.

    2. Dbs5347

      The problem with this logic is that the Chinese government without a shadow of a doubt has the legal authority over Chinese companies to force them to backdoor equipment. The US government has no such legal authority over US companies. It has also tried this with apple and been rebuffed. It is therefore NOT equally probable that US and Chinese companies have installed government demanded backdoors on a wide scale. Very probable for China, possible but not probable for the US.

      1. Claptrap314 Silver badge

        I am particularly fond of when they sent NSLs to the major shipping companies redirecting all packages sent to particular addresses to a classified location wherein certain modifications were made to the items being shipped.

    3. Anonymous Coward
      Anonymous Coward

      Or buy a US device made in China to ensure you get the best backdoors of both worlds...

  2. tekHedd

    Oh I doubt...that it was just US equipment we hacked

    The claim is that the US engaged in cyber attacks, and *only* targeted backdoors in US made equipment? Now THAT is what I call BS. Obviously we would have used any exploits we know about, including those in Chinese-made equipment. Is there perhaps some doubt that the NSA knows where the backdoors are? That they don't have a stash of 0-days in reserve?

    We might have hypocritical propaganda, but we're not stupid.

  3. Anonymous Coward
    Anonymous Coward

    All backdoors eventually get leaked..

    As per the title, all backdoors will eventually get discovered or leaked and spread across the world.

    The most recent case of the iPhone malware called Coruna was suspected to be leaked by the government contractor L3Harris by a rogue employee.

    But the earlier version of the malware was discovered by the researchers at Kaspersky Labs when they discovered unusual network traffic coming from their own employees iPhones and they were able to extract and decompile the malware which led to the mystery of how the malware developers were able to exploit an undocumented and unused section of Apple's hardware.

    I highly suggest you read Kaspersky's fascinating reverse engineering of the iPhone malware and the fuzzing of Apples chips. It does raise many questions in the "Last Hardware Mystery" link below:

    https://techcrunch.com/2026/03/10/us-military-contractor-likely-built-iphone-hacking-tools-used-by-russian-spies-in-ukraine/

    https://securelist.com/operation-triangulation-the-last-hardware-mystery/111669/

    1. Anonymous Coward
      Anonymous Coward

      Re: All backdoors eventually get leaked..

      Our guess is that this unknown hardware feature was most likely intended to be used for debugging or testing purposes by Apple engineers or the factory, or that it was included by mistake. Because this feature is not used by the firmware, we have no idea how attackers would know how to use it.

      I'd suggest that the chip design that was approved to be sent to the Fab wasn't the chip design used by the Fab.

      1. retiredFool Silver badge

        Re: All backdoors eventually get leaked..

        Years back, a friend who does litho told me DARPA had been sending out feelers for how to verify a chip was what you thought it was. Because of that very reason. I remember thinking at the time that is crazy and a very poor way to ensure both that your design doesn't leak to a foreign entity and that your design isn't modified by a foreign entity.

  4. Groo The Wanderer - A Canuck Silver badge

    Anybody who thinks the USG has no backdoors into America products is a complete and utter fool. The very first thing someone who feels guilty about doing something does is accuse the opposition of doing the same thing, but for evil intent. Enter the claims about Chinese back doors.

    Meanwhile the European vendors sit on the sidelines and giggle at the political theatre the two "world powers" bicker over.

    Every government with a bent for surveillance has such back doors into their nation's products. And the vendors based there will deny it to the end because the back doors are "national security" issues that result in hard jail time if you talk about them, the same as if you were working for the military.

    1. Anonymous Coward
      Anonymous Coward

      If you think its the same as if working for the military, you're naive. Militaries have rules, governments don't.

    2. SundogUK Silver badge

      Also:

      Anybody who thinks the CCP has no backdoors into Chinese products is a complete and utter fool.

  5. DoctorNine Silver badge

    Willie Dixon

    "..the men don't know, but the little girls, they understand..."

  6. theModge

    Back in the day getting passed Irianian internet censorship had a price

    An Iranian friend tells me an internet connection that could get porn was a thing one could bribe an official for back when he lived there (15 years ago), the idea that the blockade is selective seems highly credible.

    People who can get phone signal from neighbouring nations use that as a solution too, now for contacting loved ones abroad, to assure them they're well during the war, rather than anything fun.

  7. dadbot5000

    According to Reuters, Huawei and ZTE are the largest providers of internetworking/telecom equipment to Iran, which isn't surprising since China and Iran used to have a cozy relationship. It is also almost certain that Chinese telecom equipment has built-in backdoors for the CCP to snoop on communications. No doubt US operatives are well aware of these exploits and possibly used them during Epic Fury. It is a war, after all.

    1. retiredFool Silver badge

      It was an illegal attack by the us, not a war. Plain and simple. And I'd like to see everyone involved from el trumpie to kushner to hegs to marco charged with war crimes and have them spend the rest of their lives in prison for it. It is no different than what russia did to ukraine.

      1. Groo The Wanderer - A Canuck Silver badge
  8. Dbs5347

    The most likely explanation is that 1. Iran's networks are not as isolated as they think they are. 2. That precious little is actually secured from state actor cyberwarfare even without an intentionally designed back door. 3. That Israeli and US intelligence achieved persistence on networks of interest in Iran long ago.

  9. PWgr

    How much Cisco gear even exists in Iran. Have to imagine most routers are Huawei with bootleg OS from 2000's. More vulnerabilities than Swiss cheese. Who needs backdoors.

    1. Jellied Eel Silver badge

      How much Cisco gear even exists in Iran.

      Lots. Sanctions only really work when people play by the rules, but money is money. So Iran and other sanctioned countries have often created businesses outside their borders. Set up a systems integrator or Cisco reseller/distributor in say, the UAE, Pakistan, Indonesia etc and ship some of the tin into Iran. Or disties might prefer money over the risk or threat of penalties for violating US or EU law and sell to Iranian entities anyway. Cisco's compliance people might try and conduct audits to spot sanction violations, but there's a lot of tin and probably not many compliance people. Then there's the second hand market as well.

      But it's something I've encountered a few times. Sales get excited about a deal into Iran. I point out that it's illegal and we can't ship tin there. Then it's the Iranian customer can supply the tin, can't we just manage it? And much the same answer, and if they'd want their commission paid into their commissary card. It's never been hard to supply, it's just the penalties for violating sanctions can be severe, with large fines and jail time for anyone involved in those deals. But I also had a curious contract offer from a well-known company via an arms-length subsidiary. Part of the contract included a pseudo-idemnity that if they got caught, they'd provide substantial legal expenses and compensation.. But as what they were proposing was outright illegal in the first place, I declined their generous offer. I was tempted at the time to report that one to TPTB, but there were also hints from the client that TPTB already knew.. But not a risk I was prepared to take

      The safe way though is to just apply for and be granted a licence, which happened one time, but more often applications were just refused.

      Vendor compliance has probably been made a bit easier with stuff like Cisco's PITA licence and update systems, and the potential to geolocate where tin might be sitting, then if vendors can give that tin a 'special' software version, or TPTB can insert that. But the politics can sometimes get interesting. So clients in the Middle East might specify no Israeli products, but the US has Israeli boycotts illegal. Then figuring out what, if any risks might be when things like Ethernet chipsets or SFPs contain their own microcode and might end up being used for something nefarious.

  10. Anonymous Coward
    Anonymous Coward

    Dirty deeds

    For a fee, I'm happy to be

    Your back-door man, hey

  11. Andy3

    'Chinese state media has seized on the Iranian reports to restate Beijing’s position that China is a pacifist in cyberspace'. Oh of course, I was forgetting....

  12. In the company of clowns

    It should be no surprise. About 15 years ago, I can remember the CIA/NSA backdoor chip was even listed on the Cisco product specification list for new routers and switches.

  13. heyrick Silver badge

    Hypothesise the presence of a back door?

    I'd be quite surprised if there wasn't such a thing.

  14. Anonymous Coward
    Anonymous Coward

    If you haven't figured out already...

    Cuba, Venezuela, Iran ... all (Belt and Road?) buddies of China.

    Iran is a side quest or bonus quest. The final boss is China.

    Once Iran is dealt with, I expect some action to commence in the Straits of Malacca and South China Sea. Refer to the recent US-Indonesia defence agreement signed. Combine that with Australia, Philippines, Taiwan and a Japan which might remove the post-WW2 pacifist shackles. And I believe Singapore was caught red-handed smuggling nVidia A.I chips and Iranian oil to China last year.

    I also expect Russia to backstab China at some point depending on some conditions, thus ending the Russia-China marriage of convenience, formed in 2022.

    It'll be a super exciting year, to say the least.

    TLDR: China is fecked.

    1. amanfromMars 1 Silver badge

      Re: If you haven't figured out already...

      That diatribe is worthy of Jackanory, AC. Bravo.

      1. heyrick Silver badge
        Happy

        Re: If you haven't figured out already...

        Following link to wiki-pee:

        Coverage of the live broadcast of the Apollo 8 mission in 1968 was interrupted so Jackanory could be shown.

        Priorities.

    2. Groo The Wanderer - A Canuck Silver badge

      Re: If you haven't figured out already...

      The only thing "fecked" is the people at ground zero when the bombs drop, and the people who survive at the fringes of the radiation fallout are double-fecked because now they've got to deal with psychos fighting over society's scraps and leftovers.

      The billionaires and autocrats will be just fine in their bunkers and bomb shelters, often luxuriously appointed far beyond anything we'd ever be living in. And that's what they consider "roughing" it.

  15. amanfromMars 1 Silver badge

    FFS Stop whining. Just find any of the Magic AI Buttons and press them for more than Just Fun Runs

    All governments are absolutely useless at not having to spy on everything and everyone in order to keep themselves and their backers in clover and their multiple enemies in the dark and pig ignorant about that which is able to disable and topple them.

    What do you think AI is really for ‽ The reinforcing of a whole host of right dodgy shadowy infrastructures/exoskeletons or ITs fast flash cash crashing of them?

  16. WSWS

    It's plausible that the US might have backdoors - though hoarded zero-days are perhaps more likely. It's just as plausible that Iran are lying. What is in no way plausible and you're an idiot if you believe it is that China does not have any backdoors in *their* hardware.

Page:

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon