PSA for the travellers here - the PRC is getting more bold

So I needed a hotspot for a bit, got some generic looking thing from the vendor* and it was fine for awhile then started flaking out, they were good about it and shipped a replacement right away.

Replacement is a nice shiny new Huawei, the SSID is “Huawei_xxxx_xxxx”, where the first one was “VendorName_xxxx_xxxx”, so I plug it in with mild trepidation, connect, and first thing go to NTU Speed5 as that was my test case to show the first one was dying.

And I end up on a speed-test page, but it’s not NTU, it’s Huawei’s!

Wtf? So I double check everything and sure enough, they’re intercepting DNS. Okay, that’s highly annoying, but not unheard of, plenty of “captive” hotspots at cafes or whatever do that too, that’s what VPNs are for.

Except the damn thing isn’t just intercepting DNS, it’s trying to mitm all secure connections - every site with a “pinned” certificate (including my normal VPN) - is throwing cert errors left and right. :angry_face_with_horns:

Fortunately seems to be ignoring UDP so my backup VPN should be okay, but JFC - they weren’t even trying to hide it or even be clever about it, most brazen :poop: I’ve ever seen! :expressionless_face:

So just watch out for that if you get a Chinese-made hotspot anywhere now.


*(I didn’t name the service provider as they are a well-known Japanese company and I don’t think they’re responsible for this - I think they just got in a shipment of new hotspots and started sending them out unaware they were backdoored.)

From my understanding, all network devices for the Chinese market need to have those root certificates installed which have a government backdoor. It’s part of the Great Firewall. Because you’re using a non-Chinese browser on your computer, it will (rightfully!) flag this certificate as invalid / insecure. A browser from China would probably accept this certificate without warnings.

I would disagree: If they import these devices into Taiwan, they need to make sure they follow local laws, i.e. that they don’t contain Chinese backdoors. They probably bought devices meant for the Chinese market at a cheaper price…

You probably could complain to the NCC (I think they’re in charge of approving Wifi devices and might be interested that someone is distributing backdoored devices in Taiwan)…

for a concerned non-techie, how could I check for this stuff on my own routers?

If you use a modern browser (Chrome, Edge, Firefox, …) and keep it up-to-date, they would usually warn you about this happening unless someone has specifically modified (“hacked”) your device.

Otherwise, you can check the security settings of a website (usually by clicking the lock sign or similar in the address bar) - e.g. on iOS under “Connection Security Details”:

Especially pay attention to the first certificate in line, i.e. the root certificate. Basically, that one is the broadest:

You can then verify that no “suspicious” Certificate is in the chain (either Google the issuing authorities or ask an AI agent for help) - if you spot a certificate issued in China or similar, be very suspicious!

In case of the manipulated router, the root certificate would be issued by the Chinese Government (or a related party).

Eaaaj. Another rabbit hole for me to explore!:joy:

If you’re going down that hole: Many careless vendors (also a lot of those in Taiwan…) install root certificates on a machine while installing their product.

That means that your computer will subsequently trust every certificate signed by that root certificate - even outside the intended scope. If that vendor then gets hacked (or worse: They publish their private key accidentally or on purpose), attackers can easily take over every computer which is running that kind of software.

With the help of ChatGPT some prominent examples:

  • Lenovo / Superfish (2015): Lenovo preinstalled Superfish adware, which added its own root CA so it could intercept and modify HTTPS traffic. Weak implementation and a recoverable shared private key allowed attackers to forge trusted certificates and perform man-in-the-middle attacks. — WIRED (WIRED)
  • Dell / eDellRoot (2015): Dell support software installed a trusted root certificate together with its private key. The same easily extracted key appeared on multiple computers, allowing attackers to impersonate HTTPS sites or intercept encrypted communications. — WIRED (WIRED)
  • PrivDog / Comodo-affiliated software (2015): PrivDog installed a self-generated root CA and intercepted HTTPS to replace advertisements. A faulty version failed to validate the real website certificates, effectively accepting fraudulent certificates from any attacker. — PCWorld (PCWorld)

Taiwan-specific examples

  • Savitech USB audio drivers (2017): Taiwan-based Savitech silently installed a broadly trusted SaviAudio root CA through USB audio-driver packages distributed by ASUS and other hardware vendors. It was originally added for Windows XP driver signing, remained installed after updates, and could have become catastrophic had Savitech’s private key been compromised. — BleepingComputer (BleepingComputer)
  • Changingtec ServiSign: This widely used Taiwanese government and financial-service component installs the private Changing Certificate Authority 2015 CA into browser or Windows trusted-root stores so websites can communicate with a local ServiSign service over HTTPS. The CA key was not publicly reported as compromised, but vulnerable ServiSign versions subsequently allowed remote code execution and arbitrary file access, illustrating the additional attack surface created by such privileged local components. — TWCERT/CC advisory and installation documentation

Oh, wow, I didn’t know about that one - that’s really bad. :sweat_smile:

ETA: I just looked it up and am really shocked that I missed it, especially as it came right after the Lenovo thing.

For those of us who have no idea what this all
Means, what’s all this mean?

OP bought a pocket wifi router from a big retailer in Taiwan - turns out it’s bugged in a very obvious way by the Chinese.

How do we know the OP is really @bz ?? :runaway:

Technically you never did… :popcorn:

Just rented for a few days and already returned, but interestingly, since you explained about the illegality here and mentioned the NCC complaint option (thank you for both!), I disabled the VPN for a bit to poke at it more, maybe save some certs or whatever (since I don’t have an SDR here for packet captures from the upstream), so I could make it a proper report with evidence, and… I couldn’t! It had stopped screwing around! :expressionless_face:

In fairness to Huawei, my best guess is they have a standard base firmware with the core functionality and then enable/disable “features” based on location and it just needed a reboot or something for the disablement to take effect.

(But for the folks following along here it’s always best to assume any Chinese device is always listening for the right port knock or magic packet or whatever to enable some kind of shenanigans. :unamused_face:)

ngl that’s terrifying lol. I’d be so paranoid after that. Definitely stop using it and switch to a different provider. Also change your passwords for anything you accessed while using it. That kind of interception is not normal even for cheap hotspots.

Yeah, but pretty much par for the course for generic free wifi from small business. The average local cafe is typically just running some crappy little device with firmware that hasn’t been updated since they bought it and is completely compromised now.

The unusual things here were that it was a device that would not typically be compromised (as you said there) and that it was so obvious - most bad actors will ensure that their malware only acts on connections that can be intercepted “quietly”, this thing was stupid/noisy as hell!

And of course, always 2FA All The Things!

(Forumosa ironically being one site that wasn’t, but I see it’s supported now - done! Thanks @GooseEgg!!! :folded_hands: )

Similar thing can happen when one buys a very cheap eSIM for internet service.

You mean the radio chipset vulnerabilities? Eyup… :expressionless_face:

No. eSIM can route your internet traffic in unexpected ways, like through Chinese servers. And they can determine the DNS servers for the connection unless you override them.

If there’s anything that the world should band together to reject any product from China, it should probably start with the networking and telecommunication industries.

There are eSIM attack vectors, but I’ve never heard of these, can you explain more? :thinking:

Or maybe I’m just reading that too narrowly, are you referring to malicious profiles? Or just that the packet gateway (or even the entire eSIM provider company) could be Chinese-owned?

The operator of the eSIM has a lot of control over your phone’s connection where a lot of your most important communication runs through.

Below is a more precise explanation of the issues by Claude: