X
Edition:
United States

  • Business
    • Business Home
    • Legal
    • Deals
    • Aerospace & Defense
    • Finance
    • Autos
    • Reuters Summits
    • Data Dive
  • Markets
    • Markets Home
    • U.S. Markets
    • European Markets
    • Asian Markets
    • Global Market Data
    • Indices
    • Stocks
    • Bonds
    • Currencies
    • Comm & Energy
    • Futures
    • Funds
    • Earnings
    • Dividends
  • World
    • World Home
    • U.S.
    • Special Reports
    • Reuters Investigates
    • Euro Zone
    • Middle East
    • China
    • Japan
    • Mexico
    • Brazil
    • Africa
    • Russia
    • India
  • Politics
    • Politics Home
    • Election 2016
    • Polling Explorer
    • Just In: Election 2016
    • What Voters Want
    • Supreme Court
  • Tech
    • Technology Home
    • Science
    • Top 100 Global Innovators
    • Environment
    • Innovation
  • Commentary
    • Commentary Home
    • Podcasts
  • Breakingviews
    • Breakingviews Home
    • Breakingviews Video
  • Money
    • Money Home
    • Retirement
    • Lipper Awards
    • Analyst Research
    • Stock Screener
    • Fund Screener
  • Life
    • Health
    • Sports
    • Arts
    • Entertainment
    • Oddly Enough
    • Faithworld
  • Pictures
    • Pictures Home
    • The Wider Image
    • Photographers
    • Focus 360
  • Video
ZTE confirms security hole in U.S. phone
  • Africa
    América Latina
  • عربي
    Argentina
  • Brasil
    Canada
  • 中国
    Deutschland
  • España
    France
  • India
    Italia
  • 日本
    México
  • РОССИЯ
    United Kingdom
  • United States
Technology News | Fri May 18, 2012 | 3:07am EDT

ZTE confirms security hole in U.S. phone

Employees of ZTE chat on the roof of its headquarters in Shenzhen, Guangdong province, April 17, 2012. REUTERS/Tyrone Siu
Employees of ZTE chat on the roof of its headquarters in Shenzhen, Guangdong province, April 17, 2012. REUTERS/Tyrone Siu
By Jeremy Wagstaff and Lee Chyen Yee

ZTE Corp, the world's No.4 handset vendor and one of two Chinese companies under U.S. scrutiny over security concerns, said one of its mobile phone models sold in the United States contains a vulnerability that researchers say could allow others to control the device.

The hole affects ZTE's Score model that runs on Google Inc's Android operating system and was described by one researcher as "highly unusual."

"I've never seen it before," said Dmitri Alperovitch, co-founder of cybersecurity firm, CrowdStrike. The hole, usually called a backdoor, allows anyone with the hardwired password to access the affected phone, he added.

ZTE and fellow Chinese telecommunications equipment manufacturer, Huawei Technologies Co Ltd, have been stymied in their attempts to expand in the United States over concerns they are linked to the Chinese government, though both companies have denied this.

Most such concerns have centered on the fear of backdoors or other security vulnerabilities in telecommunications infrastructure equipment rather than in consumer devices.

Last month a U.S. congressional panel singled out Huawei and ZTE by approving a measure designed to search and clear the U.S. nuclear-weapons complex of any technology produced by the two companies.

Reports of the ZTE vulnerability first surfaced this week in an anonymous posting on the code-sharing website, pastebin.com. Others have since alleged that other ZTE models, including the Skate, also contain the vulnerability. The password is readily available online.

ZTE said it had confirmed the vulnerability on the Score phone, but denied it affected other models.

"ZTE is actively working on a security patch and expects to send the update over-the-air to affected users in the very near future," ZTE said in an emailed statement. "We strongly urge affected users to download and install the patch as soon as it is rolled out to their devices."

Alperovitch said his team had researched the vulnerability and found that the backdoor was deliberate because it was being used as a way for ZTE to update the phone's software. It is a question, he said, of whether the purpose was malicious or just sloppy programming.

"It could very well be that they're not very good developers or they could be doing this for nefarious purposes," he said.

While security researchers have highlighted security holes in Android and other mobile operating systems, it is rare to find a vulnerability apparently inserted by the hardware manufacturer.

"I have never seen this before. There are rumors about backdoors in Chinese equipment floating around," Alperovitch said. "That's why it's so shocking to see it blatantly on a device."

A Google spokesman declined to comment.

(Reporting by Jeremy Wagstaff and; Lee Chyen Yee; Editing by Matt Driskill)

Next In Technology News

U.S. self-driving sensor maker Savari announces partnership with China's SAIC Motor

BEIJING Savari Inc, a U.S. maker of sensors for autonomous driving, on Tuesday said China's largest automaker, SAIC Motor Corp Ltd, has agreed to manufacture and distribute Savari's sensors in China and some Southeast Asian markets.

Uber's Otto hauls Budweiser across Colorado in self-driving truck

SAN FRANCISCO In the first real-world commercial use of autonomous trucking, some 45,000 cans of Budweiser beer arrived late last week to a warehouse after traveling over 120 highway miles in a self-driving truck with no driver at the wheel, executives from Uber [UBER.UL] and Anheuser-Busch said.

Netflix CEO gives conditional approval of AT&T-Time Warner deal

Netflix Chief Executive Reed Hastings said he was in favor of AT&T Inc's planned $85.4 billion acquisition of Time Warner Inc, provided that his popular media streaming company continued to be treated fairly.

MORE FROM REUTERS

Sponsored Content

From Around the Web Promoted by Taboola

Trending Stories

    Editor's Pick

    LIVE: Election 2016

    Pictures

    Photos of the day

    Sponsored Topics

    X
    Follow Reuters:
    • Follow Us On Twitter
    • Follow Us On Facebook
    • Follow Us On RSS
    • Follow Us On Instagram
    • Follow Us On YouTube
    • Follow Us On LinkedIn
    Subscribe: Feeds | Newsletters | Podcasts | Apps
    Reuters News Agency | Brand Attribution Guidelines

    Reuters is the news and media division of Thomson Reuters. Thomson Reuters is the world's largest international multimedia news agency, providing investing news, world news, business news, technology news, headline news, small business news, news alerts, personal finance, stock market, and mutual funds information available on Reuters.com, video, mobile, and interactive television platforms. Learn more about Thomson Reuters products:

    Eikon
    Information, analytics and exclusive news on financial markets - delivered in an intuitive desktop and mobile interface
    Elektron
    Everything you need to empower your workflow and enhance your enterprise data management
    World-Check
    Screen for heightened risk individual and entities globally to help uncover hidden risks in business relationships and human networks
    Westlaw
    Build the strongest argument relying on authoritative content, attorney-editor expertise, and industry defining technology
    ONESOURCE
    The most comprehensive solution to manage all your complex and ever-expanding tax and compliance needs
    CHECKPOINT
    The industry leader for online information for tax, accounting and finance professionals

    All quotes delayed a minimum of 15 minutes. See here for a complete list of exchanges and delays.

    • Site Feedback
    • Corrections
    • Advertise With Us
    • Advertising Guidelines
    • AdChoices
    • Terms of Use
    • Privacy Policy